Official, verified IP ranges for third-party services. Machine-readable, with provenance.
| Slug | Service | Classification | Purposes (entries v4+v6) | Ranges |
aws | Amazon Web Services | dedicated | all (egress, 1735+2368)
cloudfront (egress, 180+31)
dynamodb (egress, 29+0)
route53-healthchecks (ingress, 27+23)
s3 (egress, 171+579) | json |
azure | Microsoft Azure (Service Tags) | dedicated | all (egress, 895+1232)
sql (egress, 1115+402)
storage (egress, 496+80) | json |
digitalocean | DigitalOcean | dedicated | all (egress, 181+53) | json |
google | Google (all services) | dedicated | all (egress, 130+15) | json |
google-cloud | Google Cloud Platform | dedicated | africa-south1 (egress, 6+2)
all (egress, 448+28)
asia-east1 (egress, 30+2)
asia-east2 (egress, 11+2)
asia-northeast1 (egress, 26+2)
asia-northeast2 (egress, 11+2)
asia-northeast3 (egress, 17+2)
asia-south1 (egress, 32+2)
asia-south2 (egress, 14+2)
asia-southeast1 (egress, 43+3)
asia-southeast2 (egress, 16+2)
asia-southeast3 (egress, 4+2)
australia-southeast1 (egress, 25+2)
australia-southeast2 (egress, 8+2)
europe-central2 (egress, 8+2)
europe-north1 (egress, 8+2)
europe-north2 (egress, 4+2)
europe-southwest1 (egress, 9+2)
europe-west10 (egress, 4+2)
europe-west12 (egress, 11+2)
europe-west15 (egress, 4+1)
europe-west1 (egress, 55+2)
europe-west2 (egress, 36+2)
europe-west3 (egress, 31+2)
europe-west4 (egress, 37+2)
europe-west6 (egress, 10+2)
europe-west8 (egress, 15+2)
europe-west9 (egress, 7+2)
global (egress, 43+1)
me-central1 (egress, 6+2)
me-central2 (egress, 15+2)
me-west1 (egress, 12+2)
northamerica-northeast1 (egress, 24+2)
northamerica-northeast2 (egress, 11+2)
northamerica-south1 (egress, 4+2)
southamerica-east1 (egress, 14+2)
southamerica-west1 (egress, 14+2)
us-central1 (egress, 107+2)
us-central2 (egress, 12+2)
us-east1 (egress, 48+2)
us-east4 (egress, 51+2)
us-east5 (egress, 17+2)
us-east7 (egress, 8+2)
us-south1 (egress, 18+2)
us-west1 (egress, 61+2)
us-west2 (egress, 21+2)
us-west3 (egress, 14+2)
us-west4 (egress, 13+2)
us-west8 (egress, 4+2) | json |
ibm-cloud | IBM Cloud (Classic infrastructure) | dedicated | frontend (egress, 42+0)
load-balancers (egress, 39+0) | json |
linode | Akamai Connected Cloud (Linode) | dedicated | all (egress, 240+39) | json |
oracle-cloud | Oracle Cloud Infrastructure | dedicated | all (egress, 798+0)
object-storage (egress, 30+0) | json |
vultr | Vultr (Constant, AS20473) | dedicated | all (egress, 125+27) | json |
| Slug | Service | Classification | Purposes (entries v4+v6) | Ranges |
auth0 | Auth0 (Okta CIC) | dedicated | all (ingress, 103+0)
australia (ingress, 9+0)
canada (ingress, 6+0)
europe (ingress, 24+0)
japan (ingress, 12+0)
united-kingdom (ingress, 3+0)
united-states (ingress, 49+0) | json |
duo | Cisco Duo | dedicated | mfa-australia (egress, 2+0)
mfa-canada (egress, 2+0)
mfa-central-europe (egress, 2+0)
mfa-eu (egress, 2+0)
mfa-india (egress, 2+0)
mfa-japan (egress, 2+0)
mfa-southeast-asia (egress, 2+0)
mfa-uae (egress, 2+0)
mfa-uk (egress, 1+0)
mfa-us (egress, 4+0)
mfa (egress, 21+0)
trusted-endpoints (egress, 11+0) | json |
okta | Okta | dedicated | all (both, 2070+0)
pam-emea (both, 12+0)
pam-us (both, 19+0)
preview-emea (both, 135+0)
preview-pam (both, 18+0)
preview-us (both, 279+0)
production-australia (both, 121+0)
production-canada (both, 116+0)
production-germany (both, 414+0)
production-hipaa (both, 289+0)
production-india (both, 85+0)
production-ireland (both, 152+0)
production-japan (both, 120+0)
production-us (both, 1047+0)
us-cell-20 (both, 58+0)
us-cell-22 (both, 70+0) | json |
onelogin | OneLogin | mixed | agents-eu (egress, 4+0)
agents (egress, 10+0)
email (ingress, 2+0) | json |
workos | WorkOS | mixed | webhooks (ingress, 15+0) | json |
| Service | Vendor position |
| Twilio (REST API + webhooks) | IPs 'highly dynamic, and span a large range, so it's impractical to list each of them'; they recommend allowing outbound HTTPS to any *.twilio.com subdomain instead. SIP trunking IS pinnable, see the twilio-sip service. |
| Adyen | No IP list; allowlist out.adyen.com or resolve it via DNS hourly (their words). |
| SendGrid (webhooks/parse) | Dynamic cloud infra; use signed webhooks, not IP allowlists. |
| Slack | No published egress IPs; their allowlisting feature restricts YOUR IPs calling THEM. |
| Shopify (webhooks) | Documents HMAC-SHA256 signature verification as the way to authenticate a webhook. The page does not mention source IPs, and no official range list was found as of the verified date. |
| Square (webhooks) | No webhook source-IP list published; validate notifications via the documented HMAC-SHA256 signature flow. |
| Snowflake | Deployment-specific hostnames/IPs per account; no global list. |
| MongoDB Atlas (data plane) | Cluster IPs are per-project/dynamic; control-plane IPs only via authenticated Admin API. Vendor directs users to private endpoints (PrivateLink). |
| Vercel (function egress) | Dynamic by default; static IPs are a paid per-customer feature, not a public range. |
| JumpCloud | States for the agent, LDAP-as-a-Service and AD Integration alike: 'Due to the elastic nature of the JumpCloud infrastructure, we currently do not publish lists of IP addresses for allow lists'. Directs users to FQDNs instead. Their separate data-centre page does list six regional RADIUS anycast addresses, which is a single narrow endpoint rather than a service range set. |
| Stytch (webhooks) | Publishes no source-IP list of its own; states 'Stytch's webhooks are powered through Svix'. A receiving endpoint allowlists the svix service in this feed instead. Their own IP feature runs the other way: up to 10 customer IPs that may call the Stytch API, arranged over email with support. |
| Netlify (function egress) | States that by default the addresses builds and functions connect from 'will fluctuate when we scale up and down'. A static set is available only through the Private Connectivity add-on on Enterprise plans. |
| OpenAI API (api.openai.com) | api.openai.com resolves into Cloudflare's published ranges (verified 2026-07-30: 172.66.0.243 within 172.64.0.0/13, 162.159.140.245 within 162.158.0.0/15), so pinning it would allowlist the whole CDN rather than OpenAI. |
| Akamai (CDN) | Site Shield issues a per-customer set of IP subnet ranges (a map) retrieved through Akamai Control Center or the Site Shield API, rather than one public global list. |
| Box | Use domain names; 'IP addresses can change frequently and without notice' (their wording). No webhook source ranges published. |
| Sumo Logic | No own ranges; directs users to download the AWS IP ranges JSON and use the prefixes for the AWS region their deployment sits in, which the aws service already covers. States plainly that 'the list of IP ranges is shared infrastructure. It is not limited to Sumo Logic nodes and is subject to change over time.' |
| Oracle NetSuite (platform) | States plainly that Oracle 'does not support the use of NetSuite IP addresses to access or manage access to any NetSuite services', that outbound addresses are 'not documented in the NetSuite Help Center or in SuiteAnswers', and that *.netsuite.com is CDN-fronted. Directs users to 2FA, token-based auth and OAuth 2.0 instead, or to a DNS lookup on outboundips.netsuite.com. NetSuite Connector IS published, see the netsuite-connector service. |
| Confluent Cloud | Public egress addresses are read from the Cloud Console or the authenticated Cloud REST API (api.confluent.cloud/networking/v1/ip-addresses), are shared by every customer in the same cloud and region, and are 'not guaranteed to be static' (their wording). |
| Palo Alto Networks Prisma Access | Egress addresses are allocated per tenant and retrieved with your own API key from api.prod.datapath.prismaaccess.com, or read per location in the Prisma Access UI. |
| Splunk Cloud Platform | The documented control is an IP allow list restricting which addresses on your own network reach each Splunk feature, managed through the Admin Config Service API. Splunk publishes no ranges of its own for the stack. |
| CockroachDB Cloud | The documented controls are an allowlist of your own authorized networks and private connectivity through AWS PrivateLink, GCP Private Service Connect or Azure Private Link. |
| Redis Cloud | The CIDR allow list restricts which of your own addresses may reach your database, between 4 and 32 entries depending on plan. Redis publishes no ranges of its own. |
| Aiven | Services are addressed by hostname; static IP addresses are a paid per-project resource created and attached with the avn static-ip CLI, not a public range list. |
| Supabase | States that 'IPv4 addresses are guaranteed to be static for ingress traffic' through a per-project paid add-on, while 'the outbound IP address is not static and cannot be guaranteed'. |
| PlanetScale | The addresses to allowlist are shown in the console during the import workflow, differ by region, and the vendor directs users to read them there each time because they 'can change occasionally'. |
| Docker Hub / Docker Desktop | Publishes an allowlist of domain URLs rather than addresses; the page lists hostnames only. Reproducible on the data plane: registry-1.docker.io resolves into rotating AWS us-east-1 EC2 addresses, a different set on each query (verified 2026-07-30). |
| Mailchimp Transactional (Mandrill) webhooks | Directs users to authenticate that a webhook originated from Mailchimp's servers using the documented request-signature flow. The /ips/ API returns your own dedicated sending addresses, which is a different thing from webhook sources. |
| Honeycomb | Offers AWS PrivateLink to the Honeycomb API for Enterprise customers on AWS. No range list is published in the docs. |
| Snyk | The Broker Client opens the outbound WebSocket and Snyk rides it back, so in their words 'you do not need to allow a Snyk IP address. Instead, you can allow the Broker Client IP/port.' Requests to Snyk go through a CDN that rotates addresses and whole ranges, and they direct users to allow *.snyk.io. |
| Zapier | States that Zapier 'uses Amazon (AWS)'s us-east-1 region, where it dynamically provisions instances as needed', so there is no fixed set. They suggest matching the User-Agent: Zapier header instead, or the static IP feature available on paid plans. |
| Mailgun | Their IP Allowlist API 'lets you view and manage allowlisted IP addresses to which API key and SMTP credential usage is restricted', which controls your own callers rather than publishing Mailgun's addresses. Outbound sending addresses are per-account dedicated IPs grouped into pools, read through the authenticated /v3/ips API. |
| Dynatrace (Synthetic Monitoring) | Public Synthetic location addresses are read per environment, either from the Frequency and locations page in the web UI ('Copy IPs to clipboard or Download IPs') or from the Synthetic locations API, which 'returns all the locations available for your Environment along with their IP addresses'. No global list is published. |
| npm registry (registry.npmjs.org) | registry.npmjs.org resolves into Cloudflare's published ranges (verified 2026-07-30: 104.16.0.34 and 104.16.1.34, both inside 104.16.0.0/13), so pinning it would allowlist the whole CDN rather than npm. |
| PyPI (pypi.org, files.pythonhosted.org) | Both pypi.org and files.pythonhosted.org resolve into Fastly's published ranges (verified 2026-07-30: 151.101.0.223 and 151.101.128.223, inside 151.101.0.0/16), so pinning them would allowlist the whole CDN rather than PyPI. |
| Maven Central (repo1.maven.org) | repo1.maven.org resolves into Cloudflare's published ranges (verified 2026-07-30: 104.18.18.12 and 104.18.19.12, both inside 104.16.0.0/13), so pinning it would allowlist the whole CDN rather than Maven Central. |
| RubyGems (rubygems.org) | rubygems.org resolves into Fastly's published ranges (verified 2026-07-30: 151.101.1.227 and 151.101.129.227, inside 151.101.0.0/16), so pinning it would allowlist the whole CDN rather than RubyGems. |
| crates.io | crates.io resolves into Fastly's published ranges (verified 2026-07-30: 151.101.130.137 and 151.101.194.137, inside 151.101.0.0/16), so pinning it would allowlist the whole CDN rather than crates.io. |
| Alibaba Cloud | Publishes per-service ingress lists, such as this per-region table for Data Management Service, rather than a provider-wide range file of the kind AWS, Azure and Google publish. |