Groups
One account, several keys, one blocklist between them. What a group is, the limits per plan, the whitelist and the webhook that come with it, and how the Linux Agent and the Hive plugin each apply it.
What a group is
A group is created in your account and bundles any number of API keys, mixed freely between Linux servers running the agent and WordPress sites running Hive. When one member reports an address, every other member blocks it, for the group's window, on every port the member exposes to the community feed. A key belongs to at most one group. A key in no group behaves exactly as it always did: no extra list, no error, nothing to configure.
Manual entries and exceptions are added by hand in the portal, not on a member itself, so a change reaches every member at its next sync without anyone touching a config file. A member's own reporting address is never on the list it receives, so a group cannot lock its own members out of each other.
Limits per plan
| Free | Contributor | Professional | Business | Enterprise | |
|---|---|---|---|---|---|
| Groups per account | — | — | 1 | 3 | 100 |
| Members per group | — | — | 10 | 50 | 500 |
| Manual entries per group | — | — | 200 | 200 | 200 |
| Whitelist entries per group | — | — | 200 | 200 | 200 |
Free and Contributor see the section with an upgrade notice, but cannot create a group or put a key into one. Every derived list is capped at 20,000 entries regardless of plan, oldest entries dropped first; that cap is a health notice, not an error, and it exists to bound what any one member ever downloads or holds in the kernel. Dropping below a plan's limit is grandfathered: a group already over the new limit keeps running exactly as it is, only creating another group or adding another member is blocked until the account is back under the limit.
The whitelist of the group
A group can also carry a whitelist: addresses and prefixes, up to /24 and /64, at most 200 entries, each with a note, kept in the portal next to the group itself. No member ever blocks or reports an address on it. It changes nothing about a member's own whitelist, which keeps working exactly as before and is never replaced by it.
Webhooks
A group can carry one webhook URL. Every new ban in the group is one signed POST to it,
with an HMAC-SHA256 over the body using a secret shown in the portal, so a receiver can refuse
anything that did not come from us. The body carries the address, the reporter, the categories, when
the ban began and when it expires, and a ready-made text line for a chat tool. A delivery that fails
is retried after 60 seconds, then 300, then 1800, and then given up; the last status and the error
text stand in the portal. A second report of the same address inside the same window sends no
second webhook.
Applied by the Linux Agent
On a licensed server, the agent fetches the group list with the community feed and keeps it in its own kernel set on every port, whatever service that host exposes. It writes the group's whitelist to a file of its own and applies it in the same run, next to its local whitelist. See Blocking with the Linux Agent for the file paths, the kernel set names and the exact command output.
Applied by Hive
Hive fetches the same group list every fifteen minutes and mirrors it as blocks of its own type, so it shows up next to every other block on the Blocked IPs screen with its own badge. The group's whitelist is taken over the same way, as whitelist entries of their own origin, next to any entry you added by hand. The dashboard shows the group and its last sync, and Activity, IP Lists, Group lists every entry with the member that reported it and whether the site blocked it or why not. See Group Bans in the plugin documentation for the block type and how it interacts with the rest of the plugin.
Error codes
These are the codes the portal and the two products surface when a limit is hit or a plan does not carry groups. They never appear for a key in no group.
| Code | Meaning |
|---|---|
group_tier | The plan of this account does not carry groups. |
group_limit_reached | The account already has as many groups as its plan allows. |
group_members_full | The group already has as many members as its plan allows. |
group_manual_full | The group's manual entries are at their limit of 200. |
group_whitelist_full | The group's whitelist entries are at their limit of 200. |
Last updated: · Maintained by the ReportedIP team