For additional security and preventing un-authorized IP addresses from accessing Matomo (Piwik) dashboards, you can configure a set of white-listed (allowed) IP addresses. Since Matomo 3.6 you can also configure hostnames. However, please consider that any hostname will be resolved within each request. This may slightly slow down your Matomo.

IP addresses can be whitelisted by adding them under your [General] section in config/config.ini.php:

login_whitelist_ip[] =
login_whitelist_ip[] = 204.93.240.*
login_whitelist_ip[] =
login_whitelist_ip[] = 2001:db8::/48
login_whitelist_ip[] =

When configured, only users from a configured IP address can log into your Matomo. You can define one or multiple ; IPv4, IPv6, and IP ranges.

By default, if a whitelisted IP address is specified via login_whitelist_ip[] then both the reporting user interface as well as HTTP Reporting API requests will only work for these whitelisted IPs. But in some cases you need to allow all IP addresses access to your Matomo HTTP Reporting API endpoint. To allow all IP addresses to access the Matomo Reporting API, set in your config file under [General]:

login_whitelist_apply_to_reporting_api_requests = 0

When whitelisted IP addresses are configured and you try to access Matomo but your IP is not white-listed, you will see an error like this: “You cannot use this Matomo as your IP is not whitelisted”.

See also: How do I exclude traffic from an IP or a range of IP addresses?