SSL Certificates
Update (September 2026): Razorpay Curlec no longer publishes new SSL certificate files. The table below is provided for historical reference only, with X10 being the last certificate published. Do not pin these certificates.For the current SSL certificate policy, including certificate pinning, root certificates, certificate changes, verification steps and FAQs, see the Guidelines for SSL Certificate Rotation.
api.razorpay.com, along with their validity periods, are listed below.
These files applied to past rotations only. Do not pin or whitelist them for new integrations.
API IPs
Requests to Razorpay Curlec APIs should be routed toapi.razorpay.com. This will be resolved to various IPs controlled by our load balancers. However, if the IPs to which the requests should be sent are restricted, all your API requests can be routed to prod-api-static.razorpay.com. This will be resolved to any of the following IPs:
API Ingress IPs
Handy Tips
-
18.99.160.0/29is a CIDR range. All the IPs in the range18.99.160.48 - 18.99.160.55are utilised. - All our SDKs use proper DNS caching and honour the TTLs that we set. However, if you are not using our SDKs, ensure that DNS TTLs set by Razorpay Curlec are honoured and are not cached aggressively.
Webhook IPs
Below is the list of IPs from which Webhooks are sent from our servers.Egress IPs
UAT Static IPs
Below is the list of UAT egress IPs.UAT Egress IPs