Cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

FCrDNS alternative

We are trying to whitelist Fitbit source IPs based on recommended approach FCrDNS. But AWS API Gateway appears not to be supporting this. Is there any other way to have some access control to the updates API with AWS API Gateway?

Best Answer
0 Votes
4 REPLIES 4

I brought up a similar question a while back in this thread.  It doesn't seem like an alternative will be provided.

Best Answer

Thanks for the advise. Using the signature header is one way but, the point of doing this earlier at the gateway level is to potentially block malicious attackers from hitting the backend with many invalid requests. So I am still looking for a viable alternative.

Best Answer
0 Votes

I would appreciate if FitBit support team can advise.

Best Answer
0 Votes

This wasn't a blocker for my team, but we also would have appreciated the additional layer of security.  I was just made aware of feature requests recently and created a request to address this issue: FCrDNS Alternative - Add API Keys to Subscriptions.

Best Answer
0 Votes