---
title: "Geo-Block the Visitors to Your Online Applications"
slug: "/blog/geo-block-the-visitors-to-your-online-applications"
description: "Online applications are most susceptible to attacks today. Securing them is a need for their robustness. Here is how you can restrict the access to your online applications to the visitors from a specific region using IP Location services."
---

# Geo-Block the Visitors to Your Online Applications

By [Sheharyar Malik](https://www.linkedin.com/in/sheharyar-malik-haniel/) Senior Software Engineer

Posted on February 22, 2024 | 2 min read

![Geo-Block the Visitors to Your Online Applications](https://blogs.ipgeolocation.io/blogs-site/content/images/2026/06/geo-block-visitors-to-online-applications.svg)

Today, the online applications are most vulnerable facing a lot of cyber attacks and exploits. Some online applications or some of their contents are not available in some regions of the world. You can geo-restrict the visitors from non-availability zones on your application using IP location services like ipgeolocation.io API.

The steps to avoid unauthorized access in the restricted regions using IP location services would be:

1.  If a user visits a page on your online application, get its IP location from ipgeolocation.io API.
2.  Check if the viewed page or content on it is in restricted zone(s).
3.  Check if the user's location is in any restricted zone.
4.  If the page contains content restricted in the user's location, remove the content from the page or display a blocked message.

Here is how you can do it using ipgeolocation.io API:

Before moving on to code, you need to get an API key to use ipgeolocation.io API. If you do not have an account at [ipgeolocation.io](https://www.ipgeolocation.io/index.html), then:

*   Sign up [here](https://ipgeolocation.io/signup.html).
*   And login to [ipgeolocation.io Dashboard](https://app.ipgeolocation.io/login) and get your API key listed under the subscribed API plan.

* * *

## Geo-Block Your Visitors using ipgeolocation JQuery SDK

Open a text editor and open the page, with restricted access, of your website, say `index.html`.

Add the following script in the `head` tag of the page.

```html
<script src="https://cdn.jsdelivr.net/npm/ip-geolocation-api-jquery-sdk@1.1.2/ipgeolocation.min.js"></script>
```

Add another `script` block at the bottom of the `head` tag of the page.

```html
<script>
  // Enable sessionStorage usage to store API response on client-side. This avoids duplicate API calls for a visitor visiting multiple pages during a single visit.
  _ipgeolocation.enableSessionStorage(true);

  // Disable async calls to ipgeolocation.io API. This
  _ipgeolocation.makeAsyncCallsToAPI(false);

  // Fetch only the `country_code2` field from the response excluding rest of the response as we'll restrict access based on the country.
  _ipgeolocation.setFields("country_code2");

  // Get IP-Location for the visitor's IP address. Replace "YOUR_API_KEY" with the API key from the ipgeolocation.io dashboard.
  _ipgeolocation.getGeolocation(redirectToUnauthorizedPage, "YOUR_API_KEY");

  function redirectToUnauthorizedPage(response) {
    country_code2 = response.country_code2;

    // allow visitors only from US or CA, else redirect to security error message

    if (country_code2 === 'US' || country_code2 === 'CA') {
      window.location.href = "https://site.com/";
    } else {
      window.location.href = "https://site.com/unauthorized-access.html";
    }
  }
</script>
```

* * *

## Geo-Blocking the Visitors using PHP

Open a text editor and open the page of your website with restricted access, say `index.php`.

Add the following script in the page.

```php
<?php
  // query ipgeolocation.io API and returns JSON response
  function get_geolocation($apiKey, $ip, $lang = "en", $fields = "*") {
    $url = "https://api.ipgeolocation.io/ipgeo?apiKey=".$apiKey."&ip=".$ip."&lang=".$lang."&fields=".$fields;
    $cURL = curl_init();

    curl_setopt($cURL, CURLOPT_URL, $url);
    curl_setopt($cURL, CURLOPT_HTTPGET, true);
    curl_setopt($cURL, CURLOPT_RETURNTRANSFER, true);
    curl_setopt($cURL, CURLOPT_HTTPHEADER, array (
      "Accept: application/json"
    ));

    return curl_exec($cURL);
  }

  // get ipgeolocation for the visitor's IP address. Replace YOUR_API_KEY with your API key.
  $json = get_geolocation("YOUR_API_KEY", $_SERVER["REMOTE_ADDR"], "en", "country_code2");
  $geolocation = json_decode($json, true);
  $currentWebsite = $_SERVER["SERVER_NAME"];
  $redirect = false;
  $redirectTo = null;

  // allow visitors only from US or CA, else redirect to security error message
  if ($geolocation["country_code2"] == "US" || $geolocation["country_code2"] == "CA") {
    $redirect = false;
  } else {
    $redirect = true;
    $redirectTo = "https://site.com/unauthorized-access";
  }

  if ($redirect) {
    header("Location: ".$redirectTo);
    die();
  }
?>
```

### Related Articles

[![Residential Proxy Detection: How It Works, Why It's Hard](https://blogs.ipgeolocation.io/blogs-site/content/images/2026/07/how-residential-proxy-detection-works-comp.png)](https://ipgeolocation.io/blog/how-residential-proxy-detection-works)

[Residential Proxy Detection: How It Works, Why It's Hard](https://ipgeolocation.io/blog/how-residential-proxy-detection-works)

Residential proxies make automated traffic look like real households, which is exactly why IP reputation checks miss them. Here is how detection actually works: provider attribution, network and behavior signals, live connection analysis, and confidence scores instead of binary blocks.

Posted on July 27, 2026

By [Maaz ur Rehman](https://www.linkedin.com/in/muhammad-maaz-995494214/)

[Read More](https://ipgeolocation.io/blog/how-residential-proxy-detection-works)

[![What Is VPN Detection and How Does It Work?](https://blogs.ipgeolocation.io/blogs-site/content/images/2026/07/what-is-vpn-detection.png)](https://ipgeolocation.io/blog/what-is-vpn-detection-and-how-does-it-work)

[What Is VPN Detection and How Does It Work?](https://ipgeolocation.io/blog/what-is-vpn-detection-and-how-does-it-work)

VPN detection identifies traffic routed through VPN servers before it reaches your app. Here is how the two signal families work, what they miss, and what to do with a positive result.

Posted on July 27, 2026

By [Maaz ur Rehman](https://www.linkedin.com/in/muhammad-maaz-995494214/)

[Read More](https://ipgeolocation.io/blog/what-is-vpn-detection-and-how-does-it-work)

[![iCloud Private Relay vs Cloudflare WARP, Explained](https://blogs.ipgeolocation.io/blogs-site/content/images/2026/07/icloud-private-relay-vs-cloudflare-warp-compared.png)](https://ipgeolocation.io/blog/icloud-private-relay-vs-cloudflare-warp-explained)

[iCloud Private Relay vs Cloudflare WARP, Explained](https://ipgeolocation.io/blog/icloud-private-relay-vs-cloudflare-warp-explained)

iCloud Private Relay and Cloudflare WARP both hide a visitor's real IP address, but they are built for different jobs and hide it in different ways. Private Relay is a Safari-only, two-hop privacy relay. WARP is a whole-device tunnel through Cloudflare's network. Both keep the user near their real region, and, as you will see below, our detection API flags both as relays. If you run a website, an app, or a fraud pipeline, you meet both of these in your logs, not in an app store. This piece look

Posted on July 23, 2026

By [Sheharyar Malik](https://www.linkedin.com/in/sheharyar-malik-haniel/)

[Read More](https://ipgeolocation.io/blog/icloud-private-relay-vs-cloudflare-warp-explained)

[![IP Geolocation Data: Built, Not Guessed](https://blogs.ipgeolocation.io/blogs-site/content/images/2026/07/how-ip-geolocation-data-is-built-not-guessed-1.png)](https://ipgeolocation.io/blog/how-ip-geolocation-data-is-built)

[IP Geolocation Data: Built, Not Guessed](https://ipgeolocation.io/blog/how-ip-geolocation-data-is-built)

A lot of weak "IP geolocation data" is just a whois guess dressed up with marketing. Here is how we actually build ours, layer by layer, from registry data and geofeeds to active measurement and verification, and how accurate it really is.

Posted on July 13, 2026

By Mudassar Tariq

[Read More](https://ipgeolocation.io/blog/how-ip-geolocation-data-is-built)

[![What Is a CGI Proxy and Is It Still a Threat?](https://blogs.ipgeolocation.io/blogs-site/content/images/2026/06/CGI-Feature.png)](https://ipgeolocation.io/blog/what-is-a-cgi-proxy)

[What Is a CGI Proxy and Is It Still a Threat?](https://ipgeolocation.io/blog/what-is-a-cgi-proxy)

A CGI proxy is an old-school web proxy you use through a web page, and it leaves an obvious trace. The destination sees the proxy server's IP, not the visitor's. Here is how it works, whether it still matters, and how to flag the traffic.

Posted on June 10, 2026

By [Maaz ur Rehman](https://www.linkedin.com/in/muhammad-maaz-995494214/)

[Read More](https://ipgeolocation.io/blog/what-is-a-cgi-proxy)

[![Benefits of IP Geolocation: 8 Real Business Outcomes](https://blogs.ipgeolocation.io/blogs-site/content/images/2026/06/1.jpg)](https://ipgeolocation.io/blog/benefits-of-ip-geolocation-8-real-business-outcomes)

[Benefits of IP Geolocation: 8 Real Business Outcomes](https://ipgeolocation.io/blog/benefits-of-ip-geolocation-8-real-business-outcomes)

Eight benefits of IP geolocation that translate directly into revenue, security, and compliance outcomes, with an industry matrix showing which ones matter most for eCommerce, SaaS, AdTech, Fintech, Streaming, and regulated industries.

Posted on June 9, 2026

By [Abdullah Afzal](https://www.linkedin.com/in/abdullah-a-08ba162b7?utm_source=share&utm_campaign=share_via&utm_content=profile&utm_medium=android_app)

[Read More](https://ipgeolocation.io/blog/benefits-of-ip-geolocation-8-real-business-outcomes)
