slash0 feed

Official, verified IP ranges for third-party services. Machine-readable, with provenance.

v1/index.json · changelog · slash0.io · source & methodology · Terraform provider

Use with Terraform: data "egress_ranges" "x" { service = "<slug>" purpose = "<purpose>" }. egress purposes are ranges you connect to; ingress purposes are webhook/agent sources.

Entry counts matter: every CIDR consumes one security-group rule (default quota: 60 per SG, IPv4 and IPv6 counted separately). Aggregation is lossless: published coverage is preserved exactly and never widened. Purposes with hundreds+ of entries belong in prefix lists or firewall rule groups, not security groups.

Cloud / IaaS

SlugServiceClassificationPurposes (entries v4+v6)Ranges
awsAmazon Web Servicesdedicatedall (egress, 1735+2368)
cloudfront (egress, 180+31)
dynamodb (egress, 29+0)
route53-healthchecks (ingress, 27+23)
s3 (egress, 171+579)
json
azureMicrosoft Azure (Service Tags)dedicatedall (egress, 895+1232)
sql (egress, 1115+402)
storage (egress, 496+80)
json
digitaloceanDigitalOceandedicatedall (egress, 181+53)json
googleGoogle (all services)dedicatedall (egress, 130+15)json
google-cloudGoogle Cloud Platformdedicatedafrica-south1 (egress, 6+2)
all (egress, 448+28)
asia-east1 (egress, 30+2)
asia-east2 (egress, 11+2)
asia-northeast1 (egress, 26+2)
asia-northeast2 (egress, 11+2)
asia-northeast3 (egress, 17+2)
asia-south1 (egress, 32+2)
asia-south2 (egress, 14+2)
asia-southeast1 (egress, 43+3)
asia-southeast2 (egress, 16+2)
asia-southeast3 (egress, 4+2)
australia-southeast1 (egress, 25+2)
australia-southeast2 (egress, 8+2)
europe-central2 (egress, 8+2)
europe-north1 (egress, 8+2)
europe-north2 (egress, 4+2)
europe-southwest1 (egress, 9+2)
europe-west10 (egress, 4+2)
europe-west12 (egress, 11+2)
europe-west15 (egress, 4+1)
europe-west1 (egress, 55+2)
europe-west2 (egress, 36+2)
europe-west3 (egress, 31+2)
europe-west4 (egress, 37+2)
europe-west6 (egress, 10+2)
europe-west8 (egress, 15+2)
europe-west9 (egress, 7+2)
global (egress, 43+1)
me-central1 (egress, 6+2)
me-central2 (egress, 15+2)
me-west1 (egress, 12+2)
northamerica-northeast1 (egress, 24+2)
northamerica-northeast2 (egress, 11+2)
northamerica-south1 (egress, 4+2)
southamerica-east1 (egress, 14+2)
southamerica-west1 (egress, 14+2)
us-central1 (egress, 107+2)
us-central2 (egress, 12+2)
us-east1 (egress, 48+2)
us-east4 (egress, 51+2)
us-east5 (egress, 17+2)
us-east7 (egress, 8+2)
us-south1 (egress, 18+2)
us-west1 (egress, 61+2)
us-west2 (egress, 21+2)
us-west3 (egress, 14+2)
us-west4 (egress, 13+2)
us-west8 (egress, 4+2)
json
ibm-cloudIBM Cloud (Classic infrastructure)dedicatedfrontend (egress, 42+0)
load-balancers (egress, 39+0)
json
linodeAkamai Connected Cloud (Linode)dedicatedall (egress, 240+39)json
oracle-cloudOracle Cloud Infrastructurededicatedall (egress, 798+0)
object-storage (egress, 30+0)
json
vultrVultr (Constant, AS20473)dedicatedall (egress, 125+27)json

CDN / Edge

SlugServiceClassificationPurposes (entries v4+v6)Ranges
cloudflareCloudflarecdn-sharededge (both, 15+7)json
fastlyFastlycdn-sharededge (both, 19+2)json

Payments & fintech

SlugServiceClassificationPurposes (entries v4+v6)Ranges
braintreeBraintree (PayPal)dedicatedapi (egress, 46+0)
sandbox (egress, 102+0)
json
checkout-comCheckout.commixedwebhooks (ingress, 6+0)json
paypalPayPaldedicatedall (both, 8+0)json
plaidPlaiddedicatedwebhooks (ingress, 4+0)json
stripeStripededicatedapi (egress, 130+0)
terminal (egress, 38+0)
webhooks (ingress, 15+0)
json
wiseWisededicatedwebhooks-sandbox (ingress, 6+0)
webhooks (ingress, 7+0)
json

Observability

SlugServiceClassificationPurposes (entries v4+v6)Ranges
appdynamicsSplunk AppDynamics SaaSmixedplatform-sources (ingress, 27+0)
synthetic-agents (ingress, 57+0)
json
checklyChecklydedicatedprobes (ingress, 150+34)json
datadogDatadogdedicatedagents-eu (egress, 2+1)
agents (egress, 1+1)
api-eu (egress, 2+2)
api (egress, 1+1)
apm (egress, 1+1)
logs (egress, 1+1)
synthetics (ingress, 107+1)
webhooks (ingress, 38+0)
json
grafana-cloudGrafana Clouddedicatedalerts (ingress, 26+0)
logs (ingress, 41+0)
metrics (ingress, 67+0)
json
new-relicNew Relicdedicatedagents (egress, 5+4)
synthetics (ingress, 59+0)
json
pingdomPingdomdedicatedprobes (ingress, 148+56)json
sentrySentry (hosted)dedicatedingest (egress, 4+2)
uptime (ingress, 12+0)
webhooks (ingress, 7+0)
json
uptimerobotUptimeRobotdedicatedprobes (ingress, 102+103)json

Developer platforms & CI

SlugServiceClassificationPurposes (entries v4+v6)Ranges
buildkiteBuildkitededicatedwebhooks (ingress, 3+0)json
circleciCircleCIdedicatedcore (egress, 10+0)
jobs (ingress, 21+0)
json
githubGitHubdedicatedactions (ingress, 3718+1360)
api (egress, 24+2)
git (egress, 46+2)
hooks (ingress, 4+2)
packages (egress, 29+0)
pages (egress, 6+4)
web (egress, 34+2)
json
gitlabGitLab.commixedweb-api (egress, 2+0)
webhooks (ingress, 2+0)
json
launchdarklyLaunchDarklydedicatedservice (egress, 554+0)
webhooks (ingress, 6+0)
json
retoolRetooldedicateddefault-region (ingress, 6+0)json
svixSvixdedicatedwebhooks (ingress, 15+5)json

Data platforms

SlugServiceClassificationPurposes (entries v4+v6)Ranges
airbyteAirbyte Clouddedicatedall (ingress, 12+0)json
databricksDatabricksdedicatedall (both, 855+0)
aws-egress (egress, 32+0)
aws-ingress (ingress, 55+0)
azure-egress (egress, 85+0)
azure-ingress (ingress, 655+0)
gcp-egress (egress, 30+0)
gcp-ingress (ingress, 45+0)
json
dbt-clouddbt Clouddedicatedall (ingress, 24+0)json
elastic-cloudElastic Clouddedicatedapi (egress, 102+0)
outbound (ingress, 166+0)
json
fivetranFivetrandedicatedsync (ingress, 42+0)
webhooks (ingress, 4+0)
json
hightouchHightouchdedicatedall (ingress, 24+0)json
neonNeon (Serverless Postgres)dedicatedoutbound (ingress, 159+0)json

Identity & auth

SlugServiceClassificationPurposes (entries v4+v6)Ranges
auth0Auth0 (Okta CIC)dedicatedall (ingress, 103+0)
australia (ingress, 9+0)
canada (ingress, 6+0)
europe (ingress, 24+0)
japan (ingress, 12+0)
united-kingdom (ingress, 3+0)
united-states (ingress, 49+0)
json
duoCisco Duodedicatedmfa-australia (egress, 2+0)
mfa-canada (egress, 2+0)
mfa-central-europe (egress, 2+0)
mfa-eu (egress, 2+0)
mfa-india (egress, 2+0)
mfa-japan (egress, 2+0)
mfa-southeast-asia (egress, 2+0)
mfa-uae (egress, 2+0)
mfa-uk (egress, 1+0)
mfa-us (egress, 4+0)
mfa (egress, 21+0)
trusted-endpoints (egress, 11+0)
json
oktaOktadedicatedall (both, 2070+0)
pam-emea (both, 12+0)
pam-us (both, 19+0)
preview-emea (both, 135+0)
preview-pam (both, 18+0)
preview-us (both, 279+0)
production-australia (both, 121+0)
production-canada (both, 116+0)
production-germany (both, 414+0)
production-hipaa (both, 289+0)
production-india (both, 85+0)
production-ireland (both, 152+0)
production-japan (both, 120+0)
production-us (both, 1047+0)
us-cell-20 (both, 58+0)
us-cell-22 (both, 70+0)
json
oneloginOneLoginmixedagents-eu (egress, 4+0)
agents (egress, 10+0)
email (ingress, 2+0)
json
workosWorkOSmixedwebhooks (ingress, 15+0)json

Communications

SlugServiceClassificationPurposes (entries v4+v6)Ranges
brazeBrazededicatedconnected-content (ingress, 59+0)json
intercomIntercomdedicatedall-eu (both, 88+0)
all (both, 150+0)
outbound-webhooks (ingress, 6+0)
json
klaviyoKlaviyodedicatedintegrations (ingress, 2+0)json
pagerdutyPagerDutydedicatedwebhooks-eu (ingress, 12+0)
webhooks (ingress, 13+0)
json
postmarkPostmarkdedicatedsmtp (egress, 3+0)
webhooks (ingress, 4+0)
json
twilio-sipTwilio Elastic SIP Trunkingdedicatedsip-media (both, 1+0)
sip-signaling (both, 8+0)
json
zoomZoomdedicatedall (egress, 49+0)json

Business SaaS

SlugServiceClassificationPurposes (entries v4+v6)Ranges
atlassianAtlassian Clouddedicatedall (both, 69+14)
bitbucket (both, 40+14)
egress (ingress, 66+14)
json
docusignDocuSignmixedconnect-webhooks (ingress, 170+0)
email (ingress, 17+0)
json
hubspotHubSpotdedicatedapi (ingress, 5+0)
crawlers (ingress, 36+0)
dns (ingress, 30+0)
email (ingress, 21+0)
json
makeMakemixedplatform (ingress, 18+0)json
microsoft-365Microsoft 365mixedcommon (egress, 11+29)
exchange (egress, 15+14)
sharepoint (egress, 5+5)
teams (egress, 2+7)
json
netsuite-connectorOracle NetSuite Connectordedicatedconnector (ingress, 8+0)json
salesforceSalesforcededicatedall (both, 32+5)json
workatoWorkatodedicatedon-prem-agent (egress, 60+0)
platform (ingress, 30+0)
json
zendeskZendeskmixedapi (egress, 3+0)
webhooks (ingress, 1+0)
json

Security

SlugServiceClassificationPurposes (entries v4+v6)Ranges
netskopeNetskope (NewEdge)dedicateddataplane (both, 5+0)json
rapid7Rapid7 (InsightAppSec cloud engines)dedicatedappsec-engines (ingress, 24+0)json
tenableTenable (Vulnerability Management)dedicatedscanners (ingress, 39+17)json
zscalerZscaler (zscaler.net cloud)dedicatedannounced (egress, 48+3)
enforcement-nodes (egress, 245+49)
json

AI APIs

SlugServiceClassificationPurposes (entries v4+v6)Ranges
anthropicAnthropicdedicatedapi (egress, 1+1)
crawlers (ingress, 26+0)
outbound (ingress, 1+0)
json
openaiOpenAImixedadsbot (ingress, 2+0)
agents (ingress, 820+0)
chatgpt-user (ingress, 203+0)
connectors (ingress, 258+0)
gptbot (ingress, 17+0)
searchbot (ingress, 36+0)
json

Doesn't publish pinnable ranges

ServiceVendor position
Twilio (REST API + webhooks)IPs 'highly dynamic, and span a large range, so it's impractical to list each of them'; they recommend allowing outbound HTTPS to any *.twilio.com subdomain instead. SIP trunking IS pinnable, see the twilio-sip service.
AdyenNo IP list; allowlist out.adyen.com or resolve it via DNS hourly (their words).
SendGrid (webhooks/parse)Dynamic cloud infra; use signed webhooks, not IP allowlists.
SlackNo published egress IPs; their allowlisting feature restricts YOUR IPs calling THEM.
Shopify (webhooks)Documents HMAC-SHA256 signature verification as the way to authenticate a webhook. The page does not mention source IPs, and no official range list was found as of the verified date.
Square (webhooks)No webhook source-IP list published; validate notifications via the documented HMAC-SHA256 signature flow.
SnowflakeDeployment-specific hostnames/IPs per account; no global list.
MongoDB Atlas (data plane)Cluster IPs are per-project/dynamic; control-plane IPs only via authenticated Admin API. Vendor directs users to private endpoints (PrivateLink).
Vercel (function egress)Dynamic by default; static IPs are a paid per-customer feature, not a public range.
JumpCloudStates for the agent, LDAP-as-a-Service and AD Integration alike: 'Due to the elastic nature of the JumpCloud infrastructure, we currently do not publish lists of IP addresses for allow lists'. Directs users to FQDNs instead. Their separate data-centre page does list six regional RADIUS anycast addresses, which is a single narrow endpoint rather than a service range set.
Stytch (webhooks)Publishes no source-IP list of its own; states 'Stytch's webhooks are powered through Svix'. A receiving endpoint allowlists the svix service in this feed instead. Their own IP feature runs the other way: up to 10 customer IPs that may call the Stytch API, arranged over email with support.
Netlify (function egress)States that by default the addresses builds and functions connect from 'will fluctuate when we scale up and down'. A static set is available only through the Private Connectivity add-on on Enterprise plans.
OpenAI API (api.openai.com)api.openai.com resolves into Cloudflare's published ranges (verified 2026-07-30: 172.66.0.243 within 172.64.0.0/13, 162.159.140.245 within 162.158.0.0/15), so pinning it would allowlist the whole CDN rather than OpenAI.
Akamai (CDN)Site Shield issues a per-customer set of IP subnet ranges (a map) retrieved through Akamai Control Center or the Site Shield API, rather than one public global list.
BoxUse domain names; 'IP addresses can change frequently and without notice' (their wording). No webhook source ranges published.
Sumo LogicNo own ranges; directs users to download the AWS IP ranges JSON and use the prefixes for the AWS region their deployment sits in, which the aws service already covers. States plainly that 'the list of IP ranges is shared infrastructure. It is not limited to Sumo Logic nodes and is subject to change over time.'
Oracle NetSuite (platform)States plainly that Oracle 'does not support the use of NetSuite IP addresses to access or manage access to any NetSuite services', that outbound addresses are 'not documented in the NetSuite Help Center or in SuiteAnswers', and that *.netsuite.com is CDN-fronted. Directs users to 2FA, token-based auth and OAuth 2.0 instead, or to a DNS lookup on outboundips.netsuite.com. NetSuite Connector IS published, see the netsuite-connector service.
Confluent CloudPublic egress addresses are read from the Cloud Console or the authenticated Cloud REST API (api.confluent.cloud/networking/v1/ip-addresses), are shared by every customer in the same cloud and region, and are 'not guaranteed to be static' (their wording).
Palo Alto Networks Prisma AccessEgress addresses are allocated per tenant and retrieved with your own API key from api.prod.datapath.prismaaccess.com, or read per location in the Prisma Access UI.
Splunk Cloud PlatformThe documented control is an IP allow list restricting which addresses on your own network reach each Splunk feature, managed through the Admin Config Service API. Splunk publishes no ranges of its own for the stack.
CockroachDB CloudThe documented controls are an allowlist of your own authorized networks and private connectivity through AWS PrivateLink, GCP Private Service Connect or Azure Private Link.
Redis CloudThe CIDR allow list restricts which of your own addresses may reach your database, between 4 and 32 entries depending on plan. Redis publishes no ranges of its own.
AivenServices are addressed by hostname; static IP addresses are a paid per-project resource created and attached with the avn static-ip CLI, not a public range list.
SupabaseStates that 'IPv4 addresses are guaranteed to be static for ingress traffic' through a per-project paid add-on, while 'the outbound IP address is not static and cannot be guaranteed'.
PlanetScaleThe addresses to allowlist are shown in the console during the import workflow, differ by region, and the vendor directs users to read them there each time because they 'can change occasionally'.
Docker Hub / Docker DesktopPublishes an allowlist of domain URLs rather than addresses; the page lists hostnames only. Reproducible on the data plane: registry-1.docker.io resolves into rotating AWS us-east-1 EC2 addresses, a different set on each query (verified 2026-07-30).
Mailchimp Transactional (Mandrill) webhooksDirects users to authenticate that a webhook originated from Mailchimp's servers using the documented request-signature flow. The /ips/ API returns your own dedicated sending addresses, which is a different thing from webhook sources.
HoneycombOffers AWS PrivateLink to the Honeycomb API for Enterprise customers on AWS. No range list is published in the docs.
SnykThe Broker Client opens the outbound WebSocket and Snyk rides it back, so in their words 'you do not need to allow a Snyk IP address. Instead, you can allow the Broker Client IP/port.' Requests to Snyk go through a CDN that rotates addresses and whole ranges, and they direct users to allow *.snyk.io.
ZapierStates that Zapier 'uses Amazon (AWS)'s us-east-1 region, where it dynamically provisions instances as needed', so there is no fixed set. They suggest matching the User-Agent: Zapier header instead, or the static IP feature available on paid plans.
MailgunTheir IP Allowlist API 'lets you view and manage allowlisted IP addresses to which API key and SMTP credential usage is restricted', which controls your own callers rather than publishing Mailgun's addresses. Outbound sending addresses are per-account dedicated IPs grouped into pools, read through the authenticated /v3/ips API.
Dynatrace (Synthetic Monitoring)Public Synthetic location addresses are read per environment, either from the Frequency and locations page in the web UI ('Copy IPs to clipboard or Download IPs') or from the Synthetic locations API, which 'returns all the locations available for your Environment along with their IP addresses'. No global list is published.
npm registry (registry.npmjs.org)registry.npmjs.org resolves into Cloudflare's published ranges (verified 2026-07-30: 104.16.0.34 and 104.16.1.34, both inside 104.16.0.0/13), so pinning it would allowlist the whole CDN rather than npm.
PyPI (pypi.org, files.pythonhosted.org)Both pypi.org and files.pythonhosted.org resolve into Fastly's published ranges (verified 2026-07-30: 151.101.0.223 and 151.101.128.223, inside 151.101.0.0/16), so pinning them would allowlist the whole CDN rather than PyPI.
Maven Central (repo1.maven.org)repo1.maven.org resolves into Cloudflare's published ranges (verified 2026-07-30: 104.18.18.12 and 104.18.19.12, both inside 104.16.0.0/13), so pinning it would allowlist the whole CDN rather than Maven Central.
RubyGems (rubygems.org)rubygems.org resolves into Fastly's published ranges (verified 2026-07-30: 151.101.1.227 and 151.101.129.227, inside 151.101.0.0/16), so pinning it would allowlist the whole CDN rather than RubyGems.
crates.iocrates.io resolves into Fastly's published ranges (verified 2026-07-30: 151.101.130.137 and 151.101.194.137, inside 151.101.0.0/16), so pinning it would allowlist the whole CDN rather than crates.io.
Alibaba CloudPublishes per-service ingress lists, such as this per-region table for Data Management Service, rather than a provider-wide range file of the kind AWS, Azure and Google publish.