Rate Limiting
When using public keys to authenticate calls from your frontend, you can enable fraud protection to automatically rate limit requests based on IP address and destination phone number.Enabling Fraud Protection
1
Navigate to Public Keys
Go to Public Keys in your UponAI dashboard.
2
Select your public key
Click on the public key you want to configure.
3
Enable fraud protection
Toggle on Fraud Protection and save your changes.
How It Works
When fraud protection is enabled on a public key:- Requests are rate limited based on the combination of the caller’s IP address and the destination phone number
- This prevents bad actors from using the same IP to spam calls to premium rate numbers
- Rate limiting applies to outbound phone calls and SMS initiated via public key authentication
Geographic Restrictions
Restrict which countries are allowed to make inbound calls to your UponAI phone numbers, and which countries your numbers can call outbound. This helps prevent International Revenue Sharing Fraud (IRSF) and limits exposure to unwanted traffic.Allowed Inbound Countries
1
Navigate to Phone Numbers
Go to Phone Numbers in your UponAI dashboard.
2
Select a phone number
Click on the number you want to configure.
3
Set allowed inbound countries
Under Allowed Inbound Countries, add the countries that should be allowed to call this number. Changes save automatically.
Allowed Outbound Countries
1
Navigate to Phone Numbers
Go to Phone Numbers in your UponAI dashboard.
2
Select a phone number
Click on the number you want to configure.
3
Set allowed outbound countries
Under Allowed Outbound Countries, add the countries this number should be allowed to call. Changes save automatically.
Configure via API
US, CA, GB).
Sanctioned Countries
The following countries are always blocked regardless of your configuration:
Calls to or from these countries are automatically rejected.
Best Practices
- Enable fraud protection on all public keys — adds an extra layer of protection at minimal cost
- Combine with reCAPTCHA — use both fraud protection and reCAPTCHA for web-initiated calls to prevent bot abuse
- Start with restrictive country lists — begin with only the countries you need and expand as necessary
- Monitor for blocked calls — use webhooks to track when calls are blocked due to geographic restrictions
- Review regularly — periodically review your country restrictions to ensure they match your current business needs