In the Admin Console under “Settings”, “Security,” Admins have the ability to Require Mobile Device Encryption, Restrict Exporting and Importing, enable a File Attachment Allowlist and enable an IP Range Allowlist.
Enabling this option will require iOS and Android devices to be encrypted and have a passcode. Toggle to “Enable” to turn this feature on for your entire organization.
Enabling this will prevent users from exporting a document; they won’t be able to download, export to another file type, or print from within Quip. (This won’t affect their ability to share a document with another Quip user, or to print using options outside of Quip.)
Enabling this will prevent users from importing documents, either from another service or from their local device. (Users will still be able to upload images and file attachments into documents and chat messages; use the File Attachment Allowlist to control those uploads.) You can choose between restricting imports on all platforms, or only on mobile devices.
Enabling this option will restrict file attachments, uploads, and imports across your site to the list of specified MIME types. If there are no MIME types on the allowlist, no uploads or imports will be permitted.
MIME types are validated against a known list of types; if you’re trying to allowlist a type that isn’t on our list, contact support to add it to the validated types list. You should include the entire type; for example, application/pdf (just pdf will not work) and text/plain (just text will not work).
Enabling this will restrict access to Quip to specified IP ranges to prevent your users from loading Quip content when accessing the internet from outside those ranges. If there are no ranges specified, your users will be able load Quip content from any network. (Quip traffic is always encrypted with TLS 1.2 in transit.)
To enable this for your entire organization toggle to “Enable,” enter as many IP ranges as you need in CIDR format, one per line, and then select “Enable.”
Platform management allows admins to set account-wide, platform specific restrictions for your users.
To access Platform Management, log into the Quip Admin Console and go to Settings > Security > Platform Management. Choose the dropdown arrow next to the Platform you would like to adjust and choose Manage.
Personal access tokens can be created by any user within the Quip organization by default from the quip.com/dev/token page— these are intended only for individual use and they carry the permissions of the user that generated the token.
Once the setting is toggled on and off, all active personal access tokens will be impacted and revoked. If the setting is left Enabled, Admins and users will be unable to create a new personal access token until the setting is toggled off. When the setting is toggled off, a new personal access token will need to be generated to replace the prior token generated before making a call to the Quip API.
OAuth tokens, unlike personal access tokens, are generated from API keys which can be created through the admin console by going to admin.quip.com and going into Settings -> Integrations. These are intended to be used to create shared applications & integrations and they can be scoped to have appropriate permissions for the app's use case. These will not be impacted by toggling the setting on and off. Additionally, this setting will not affect the Quip/Salesforce Integration Auth token generated when users click on the "Take the Last Step" banner in Salesforce.
All Site and Super Admins will have access to control this setting automatically. If you have a custom Admin Role you will need to modify the role to include Edit access to "Security Settings". If you are interested in additional API calls, take a look at enabling your Admin Account with Admin API Access.
000392626

We use three kinds of cookies on our websites: required, functional, and advertising. You can choose whether functional and advertising cookies apply. Click on the different cookie categories to find out more about each category and to change the default settings.
Privacy Statement
Required cookies are necessary for basic website functionality. Some examples include: session cookies needed to transmit the website, authentication cookies, and security cookies.
Functional cookies enhance functions, performance, and services on the website. Some examples include: cookies used to analyze site traffic, cookies used for market research, and cookies used to display advertising that is not directed to a particular individual.
Advertising cookies track activity across websites in order to understand a viewer’s interests, and direct them specific marketing. Some examples include: cookies used for remarketing, or interest-based advertising.