Skip to main content
Every host on your PCI Proxy destination allowlist has a status that controls whether the forward proxy may send card data to it. A destination is created in the ENABLED state and can be toggled without losing its configuration or audit history. Only ENABLED destinations are reachable. A request to a DISABLED (or removed) host is rejected with 403 DESTINATION_NOT_ALLOWED.

Workflow

A destination can be removed from either state, enabled or turned off. Removal is permanent; the record leaves the allowlist, though the deletion stays in the append-only audit log.

Destination status