Fitbit Developers oversee the SDK and API forums. We're here to answer questions about Fitbit developer tools, assist with projects, and make sure your voice is heard by the development team.
Fitbit does not support “whitelisting” of its IP addresses. Fitbit reserves the ability to scale its application dynamically to meet demand. Any attempt to whitelist Fitbit's IP addresses will result in your application breaking. Do not do this.
The authenticity of Fitbit's servers can be verified by connecting using HTTPS and validating the TLS certificate. For push requests from the Fitbit Subscriptions API, validate the X-Fitbit-Signature header and utilize forward-confirmed reverse DNS.
Best AnswerHi, @JeremiahFitbit. As of 2017-05-30, the links to the Fitbit Wiki require authentication that is not compatible with the rest of the Fitbit Community site. Is there a different way to get this information -- or a way to register for the Fitbit Wiki?
Thanks!
Best Answer
Community Moderator Alumni are previous members of the Moderation Team, which ensures conversations are friendly, factual, and on-topic. Moderators are here to answer questions, escalate bugs, and make sure your voice is heard by the larger Fitbit team. Learn more
Thanks for the reply, @AndrewFitbit, but I looked at that site and couldn't find the areas about "validate the X-Fitbit-Signature header" or "utilize forward-confirmed reverse DNS". Is there a way that you could please point me to more specific links or documentation?
Best Answer
Community Moderator Alumni are previous members of the Moderation Team, which ensures conversations are friendly, factual, and on-topic. Moderators are here to answer questions, escalate bugs, and make sure your voice is heard by the larger Fitbit team. Learn more