Skip to main content

Origin Lock: Protect your Box from direct access

Origin Lock protects your Box from direct access by only accepting requests through your proxy if they include a valid secret.

Written by Niko Baumgartl

Origin Lock is an additional security feature for customers who run their website behind a proxy.

When Origin Lock is enabled, your Box only accepts external requests if they include the HTTP header X-RDBX-Origin-Lock with the correct secret. Your proxy – for example Cloudflare – must add this header before forwarding a request to your Box.

Your website remains accessible through the proxy as usual. Direct requests to the origin without the correct secret are blocked.

Origin Lock is particularly useful if all public traffic to your website should pass through a reverse proxy.

What are an origin and a reverse proxy?

The origin is the server where your website is actually hosted – in this case, your Box at Raidboxes.

A reverse proxy sits between your visitors and your Box. It receives requests first and then forwards them to the origin.

Services such as Cloudflare, Amazon CloudFront or Fastly can act as reverse proxies and may also provide additional CDN, WAF or DDoS protection.


Why should I use Origin Lock?

Even if your domain points to a proxy such as Cloudflare, the IP address of the actual origin server may still be known.

Direct requests to the origin would bypass the proxy and therefore also its security mechanisms. Origin Lock prevents this by having your Box additionally verify a shared secret between the proxy and the origin.

Whitelisting the proxy IP ranges does not work in this case because Raidboxes uses the original visitor IP for supported proxies. Origin Lock handles this use case instead by using a shared secret between the proxy and the Box.

Do I have to use Origin Lock?

No. Origin Lock is optional and is particularly useful if your website runs behind a reverse proxy such as Cloudflare and you want to prevent the origin from being accessed directly while bypassing that proxy.

If you do not use a reverse proxy in front of your website, you should not enable Origin Lock.

How does Origin Lock work?

When Origin Lock is enabled, your Box checks the following HTTP header for external requests: X-RDBX-Origin-Lock

The header value must exactly match the secret stored in your Box settings.

  • If the secret is correct, the request is processed normally.

  • If the header is missing or the secret is incorrect, the origin responds with 403 Forbidden.

In this case, the following message is displayed in the browser:

403 Direct access to this origin is not allowed.

Internal Raidboxes system functions are not affected by Origin Lock.


How do I set up Origin Lock?

⚠️ Important: Configure the header on your proxy first and save Origin Lock at Raidboxes afterwards. If you enable Origin Lock first, requests from your proxy will be rejected with 403 Forbidden until the proxy sends the correct secret.

  1. Open your Box in the Raidboxes Dashboard and go to Settings → Security → Origin Lock.

  2. Generate a new secret using the generator icon. The built-in generator automatically creates a random 64-character secret.

  3. Copy the secret using the copy icon. You can use the eye icon to display the full value.

  4. Do not save Origin Lock yet.

  5. Open the configuration of your proxy provider.

  6. Configure the request header X-RDBX-Origin-Lock with the copied secret as a static value.

  7. Save or publish the change on your proxy.

  8. Return to the Raidboxes Dashboard and save Origin Lock.

  9. Open your website via its regular domain and check that it is accessible as usual.

Origin Lock is active as soon as you save the secret at Raidboxes.

What are the requirements for the secret?

You can either use the built-in generator or define your own secret.

The secret must meet the following requirements:

  • between 32 and 128 characters long

  • no spaces

  • the following special characters are allowed: # ? ! @ $ % ^ & * -

We recommend using the built-in generator. The automatically generated secret meets all requirements and is 64 characters long.

How do I set up Origin Lock with Cloudflare?

With Cloudflare, you can send the secret to your Box using a Request Header Transform Rule. The corresponding DNS record must be proxied through Cloudflare.

  1. Open the relevant zone in the Cloudflare Dashboard.

  2. Go to Rules.

  3. Select Create rule → Request Header Transform Rule.

  4. Give the rule a clear name, for example Raidboxes Origin Lock.

  5. Under When incoming requests match, specify which hostnames the rule should apply to.

  6. Under Modify request header, select Set static.

  7. Enter X-RDBX-Origin-Lock as the header name.

  8. Enter the secret from your Raidboxes Dashboard as the value.

  9. Save and publish the rule by selecting Deploy.

  10. Return to the Raidboxes Dashboard and save Origin Lock.

💡 Pay attention to the scope of the rule: If multiple hostnames in your Cloudflare zone point to different origins, the rule should only apply to the hostnames connected to the relevant Box. If all relevant hostnames in the zone point to the same Box, the rule can apply to all of these requests.

With Set static, Cloudflare sets the header value itself. Any existing header with the same name is overwritten.

For more information, see the Cloudflare documentation:

Can I use Origin Lock with other proxy providers?

Yes. Origin Lock is not limited to Cloudflare.

You can use any reverse proxy that can send a custom HTTP request header with a static value to the origin and overwrite an existing header with the same name.

With common providers, you can find this functionality under names such as:

Regardless of the provider, you always need the same values:

Header name: X-RDBX-Origin-Lock

Header value: your Origin Lock secret

If your proxy does not support custom request headers to the origin, you cannot use Origin Lock with that proxy.

Why do I get “403 Direct access to this origin is not allowed”?

This message means that Origin Lock is enabled for your Box, but the request does not contain the expected secret.

In this case, check the following:

  1. Is the header rule on your proxy active and published?

  2. Is the header named exactly X-RDBX-Origin-Lock?

  3. Does the secret configured on your proxy exactly match the secret in the Raidboxes Dashboard?

  4. Does the rule apply to the hostname you are using to access the website?

  5. If you use Cloudflare: Is the corresponding DNS record actually proxied through Cloudflare?

If you only receive the error when sending a direct request to the origin while your website works normally through its regular domain, Origin Lock is working as intended.

If your website is no longer accessible through the proxy either, remove the secret from the Raidboxes Dashboard and save the empty field. This disables Origin Lock and allows you to correct your proxy configuration.

How do I change my Origin Lock secret?

Since only one secret can be stored for Origin Lock at a time, you should first disable the existing secret before changing the value on your proxy.

This prevents your website from responding with 403 Forbidden while you change the secret:

  1. Go to Settings → Security → Origin Lock in your Box.

  2. Remove the existing secret completely and click Save. Origin Lock is now disabled.

  3. Generate a new secret and copy it without saving the setting yet.

  4. Change the secret for the X-RDBX-Origin-Lock header on your proxy.

  5. Save or publish the change on your proxy.

  6. Return to the Raidboxes Dashboard and save the new secret.

While Origin Lock is disabled, an X-RDBX-Origin-Lock header sent by your proxy is ignored. This prevents a 403 Forbidden response during the change.

⚠️ Important: Origin Lock is temporarily disabled between deactivating the old secret and activating the new one. Keep this window as short as possible.


How do I disable Origin Lock?

If you no longer want to use Origin Lock:

  1. Go to Settings → Security → Origin Lock in your Box.

  2. Remove the secret completely from the field.

  3. Click Save.

  4. Then remove the corresponding header rule from your proxy.

Origin Lock is now disabled and your Box no longer requires the X-RDBX-Origin-Lock header. An Origin Lock header that is still sent by your proxy has no effect while Origin Lock is disabled.

Can I exempt my own IP address from Origin Lock?

No. You currently cannot configure your own IP addresses as exceptions to Origin Lock.

An external direct request that needs to pass Origin Lock must therefore include the correct X-RDBX-Origin-Lock header with the configured secret.


📚 Related articles


Alternative keywords

This section has been added to improve article search.

Origin Lock, origin protection, secure origin, protect origin server, direct server access, block direct access, reverse proxy, proxy header, custom header, Cloudflare origin, Cloudflare proxy, Cloudflare 403, X-RDBX-Origin-Lock, Cloudflare whitelist, Cloudflare IP whitelist.

Did this answer your question?