Effective date: 25/07/2026 Action required before: 31/07/2026To strengthen the protection of order and customer data, Boxme is upgrading the security standards for all API integrations. Two changes apply to every integration. Please review and update your setup before the effective date to avoid interruption.
From the effective date, Boxme APIs only accept requests from IP addresses you have registered and we have approved. Requests from unregistered IPs will be rejected.
Register your server IP(s) via https://oms.boxme.asia > Setting and wait for approval. Registered IPs must be re-confirmed every 180 days. A reminder is sent before the due date; if not re-confirmed in time, affected connections may be rejected until updated.
When a request comes from a non-whitelisted IP, the API returns:HTTP [403] — [error code / message, e.g. IP_NOT_WHITELISTED]Handle this by ensuring the calling IP is registered and approved.