Skip to main content

Razorpay SSL Certificates

SSL certificates for api.razorpay.com with valid date ranges are tabulated below:

Certificate File | Valid From | Expiry

X3.pem & Chain | March 13th, 2020 | July 28th, 2021

X2.pem & Chain | April 10th, 2019 | April 15th, 2020

X1.pem & Chain | Feb 7th, 2016 | April 12th, 2019 As we roll out our infrastructure changes on a gradual basis, we recommend whitelisting our certificate as per Valid From/Expiry timelines. If they overlap, you should whitelist all of the certificates in that range.
We highly discourage pinning our SSL Certificate to your applications. The certificates provided, in the table above, should be used only if you are mandated by internal policies to whitelist Razorpay’s SSL Certificates. Instead, you should use the latest CA Bundle provided by your OS.

Razorpay API IPs

Requests to Razorpay APIs should be routed to api.razorpay.com. This will be resolved to various IPs controlled by our load balancers. However, in your environment, if there is a restriction of IPs to which the requests should be sent, all your API requests can be routed to prod-api-static.razorpay.com. This will be resolved to any of the following IPs:
List of API IPs

Razorpay Webhook IPs

List of Razorpay IPs from which Webhooks are sent from our servers:
List of Webhook IPs
It is highly recommended to use Webhook Signature to validate the integrity of the webhooks, even though you have whitelisted our Webhook IPs.