if the JWT is valid but the IP isn't in my service auth list, it'll still fail right?
if the JWT is valid but the IP isn't in my service auth list, it'll still fail right?

The Binding Cookie associates the browser with the Access token; the association protects against compromised authorization tokens because the origin webapp would never see this binding cookie. This protects against session hijack style attacks.
host parameter on Origin Rules locked behind a specific plan? I'm getting "not entitled to use the Origin Host override" when trying to edit itexample.com/blog to another IP / host (like blog.example.com)




hostexample.com/blogblog.example.com