Meet the new Scripe, live on October 7.Register

API v1 · 4xx

ssrf_blocked

HTTPWhen
400A webhook endpoint URL resolves to a private or restricted IP and was rejected.

Webhook receiver URLs must be HTTPS and must resolve to a public IP address. Loopback, link-local, RFC 1918 private ranges, and CGNAT ranges are all rejected — otherwise a webhook registration could be used to probe Scripe's internal network.

json
{
  "error": {
    "code": "ssrf_blocked",
    "message": "Webhook URL resolves to a private or restricted IP and was rejected.",
    "request_id": "req_…",
    "docs_url": "https://docs.scripe.io/api/v1/errors#ssrf_blocked"
  }
}

To recover, register a publicly reachable HTTPS URL. For local development, use a tunnel (ngrok, Cloudflare Tunnel) — its public hostname passes the check.

The hostname is re-resolved and re-checked on every delivery attempt, not on a schedule. A result that is private or non-routable fails that one attempt into the ordinary retry chain; it does not by itself disable the endpoint. Auto-disable comes only from the five-consecutive-failure streak. See Webhooks.