# Authentication

Learn which Moolre credentials apply to each service and how sandbox credentials differ from live credentials.

## Callback source IPs

> **Use allowlisting as an additional safeguard:** Use these addresses as one signal when verifying that a callback came from Moolre. Continue using HTTPS, validating callback payloads and transaction references, and handling callbacks idempotently.

### Wallet callbacks

- **IPv4:** `192.241.135.134`
- **IPv6:** `2604:a880:400:d1:0:3:4cf0:c001`

### POS payment-link callbacks

- **IPv4:** `174.138.44.22`
- **IPv6:** `2604:a880:400:d0::1a77:400`
