Using Cloudflare Access and Zone Lockdown?

I have a staging environment I’m trying to lock down. I need to be able to use the UI, which I can do just fine with access.

But I have another service hitting the API on staging. So I need to whitelist that IP address as well so it can get through access.

Is this doable with Access and Zone Lockdown or a firewall rule?

Actually I may have just figured this out…

edit: Well, sort of … It looks like Access is still letting API requests come through. Is this expected?

edit: okay it was letting any subdomain traffic in via api dot. Now we’re good I think!

