CLI Reference
Account Protection registers several artisan commands under the account-protection namespace. These are useful for emergency egress (e.g., when staff IPs are bl
Account Protection registers several artisan commands under the account-protection namespace. These are useful for emergency egress (e.g., when staff IPs are blocked) or for scripting changes.
Run php artisan list account-protection to view all commands.
IP Whitelist Commands
Add
# Single IP
php artisan account-protection:ip-whitelist:add 203.0.113.5 \
--notes="Finance office" \
--no-registration # optional flags disable specific bypasses
# CIDR range
php artisan account-protection:ip-whitelist:add 173.245.48.0/20 \
--notes="Cloudflare IPv4"Flags available:
--notes=– store additional context--no-registration– do not bypass registration limit--no-vpn/--no-proxy/--no-tor/--no-relay
Remove
php artisan account-protection:ip-whitelist:remove 203.0.113.5List
php artisan account-protection:ip-whitelist:listShows all whitelist entries and their bypass flags.
Clear
php artisan account-protection:ip-whitelist:clear
# add --force to skip confirmationExport
php artisan account-protection:ip-whitelist:export storage/app/ip-whitelist.json
# --format=csv to export as CSV (default is json)
# --force overwrites existing filesIf you omit the path, the command writes to storage/app/account_protection_ip_whitelist_<timestamp>.<ext>.
Import
php artisan account-protection:ip-whitelist:import storage/app/ip-whitelist.json \
--format=json \
--replace \
--force--format=is optional when the extension (.json/.csv) matches the payload.--replacewipes the current whitelist before importing (prompted unless--forceis present).- The command reports Created/Updated/Skipped counts so you can audit the load.
File Layout
JSON expects an array of objects:
[
{
"ip_address": "203.0.113.10",
"notes": "Finance office",
"bypass_registration": true,
"bypass_vpn": true,
"bypass_proxy": false,
"bypass_tor": false,
"bypass_relay": true
}
]CSV requires these lowercase headers (1/0, true/false, yes/no all map to booleans):
ip_address,notes,bypass_registration,bypass_vpn,bypass_proxy,bypass_tor,bypass_relay
203.0.113.10,Finance office,1,1,0,0,1Account Whitelist Commands
Whitelist specific user accounts to bypass VPN/proxy detection. Useful for staff or VIP customers who may use VPNs legitimately.
Add
# By email
php artisan account-protection:account-whitelist:add [email protected] \
--notes="VIP customer"
# By user ID
php artisan account-protection:account-whitelist:add 42 \
--notes="Staff member" \
--no-vpn # optional flags disable specific bypassesFlags available:
--notes=– store additional context--no-vpn/--no-proxy/--no-tor/--no-relay
Remove
php artisan account-protection:account-whitelist:remove [email protected]
# or by ID
php artisan account-protection:account-whitelist:remove 42List
php artisan account-protection:account-whitelist:listShows all whitelisted accounts with their bypass flags.
Clear
php artisan account-protection:account-whitelist:clear
# add --force to skip confirmationIP Ban Commands
Add a Ban
php artisan account-protection:ip-ban:add 198.51.100.9 \
--reason="Chargeback fraud" \
--minutes=1440 # optional expiry in minutesRelease a Ban
php artisan account-protection:ip-ban:release 198.51.100.9 \
--notes="Verified customer"List Bans
php artisan account-protection:ip-ban:list
php artisan account-protection:ip-ban:list --active # only active bansIP Log Commands
List Recent Entries
php artisan account-protection:ip-log:list --limit=50
php artisan account-protection:ip-log:list [email protected]Shows recorded login/registration IPs, timestamps, and user agents.
Email Blocklist Commands
Sync Disposable Domains
php artisan account-protection:email-blocklist:sync
# add --force to ignore the configured sync intervalThe command downloads the disposable domain list (default GitHub source), upserts entries, applies the grace-period removal policy, and prints:
- Total domains fetched and the source URL
- Added / updated / removed counts
- Pending removal count (domains that went missing but are still inside the grace window)
- A short sample of domains so you can confirm the payload
Use it inside cron or external automation. The extension also registers the command with Laravel’s scheduler when auto-sync is enabled.
Usage Tips
- Pair these commands with cronjobs or monitoring to export data regularly.
- All commands return non-zero exit codes when the requested action fails, allowing use inside scripts.
- When automating via CI/Ansible, run them from the Paymenter root (same directory as
artisan).
Troubleshooting
- If commands are missing, confirm the extension is enabled and the application is running in console mode (no cached config disabling the service provider).
- Command errors are written to
storage/logs/. Usetail -fduring execution to watch output live.
These tools provide a safety net when the admin UI is inaccessible or when swift action is required.