SSL Certificates
SSL certificates forapi.razorpay.com with valid date ranges are listed below.
Certificate File | Valid From | Expiry
X10.pem & Chain | Oct 9th, 2025 | Nov 10th, 2026
X9.pem & Chain | Nov 11th, 2024 | Dec 12th, 2025
X8.pem & Chain | Jan 5th, 2024 | Jan 4th, 2025
X7.pem & Chain | Feb 3rd, 2023 | Feb 2nd, 2024
X6.pem & Chain | May 19th, 2022 | May 19th, 2023
X4.pem & Chain | July 7th, 2021 | June 7th, 2022
X3.pem & Chain | March 13th, 2020 | July 28th, 2021
X2.pem & Chain | April 10th, 2019 | April 15th, 2020
X1.pem & Chain | Feb 7th, 2016 | April 12th, 2019 As we roll out our infrastructure changes gradually, we recommend whitelisting our certificate as per Valid From/Expiry timelines. You should whitelist all the certificates in that range if they overlap.API IPs
Requests to Razorpay APIs should be routed toapi.razorpay.com. This will be resolved to various IPs controlled by our load balancers. However, if the IPs to which the requests should be sent are restricted, all your API requests can be routed to prod-api-static.razorpay.com. This will be resolved to any of the following IPs:
API Ingress IPs
Handy Tips
-
18.99.160.0/29is a CIDR range. All the IPs in the range18.99.160.48 - 18.99.160.55are utilised. - All our SDKs use proper DNS caching and honour the TTLs that we set. However, if you are not using our SDKs, ensure that DNS TTLs set by Razorpay are honoured and are not cached aggressively.
Webhook IPs
Below is the list of IPs from which Webhooks are sent from our servers.Egress IPs
Handy Tips
18.96.225.0/26 and 18.99.161.0/26 are CIDR ranges. All the IPs in the range 18.96.225.0 - 18.96.225.63 and 18.99.161.0 - 18.99.161.63 are utilised for sending the webhooks.
We highly recommend using Webhook Signature to validate the integrity of the webhooks, even if you have whitelisted our Webhook IPs.
UAT Static IPs
Below is the list of UAT egress IPs.UAT Egress IPs