Docs › Resources › Network requirements

Network requirements

If your company filters internet traffic with a firewall, proxy or DNS filter, allow the hosts below so Redlist works for everyone. All traffic uses HTTPS on port 443. The wildcards cover only the Redlist or vendor domain shown.

Web app

  • Redlist app: app.yourredlist.com, app.redlist.software

  • App services: api-internal.yourredlist.com, api-internal2.yourredlist.com, api-internal-prod.redlist.software, api-internal-prod2.redlist.software, mobileapp.yourredlist.com, mobileapp.redlist.software

  • Files and photos: blob.prod.redlist.software, redlistv2.blob.core.windows.net

  • Public portal (QR code scans): scan.yourredlist.com, scan2.yourredlist.com

  • In-app support chat (Intercom): *.intercom.io, js.intercomcdn.com, fonts.intercomcdn.com, downloads.intercomcdn.com, static.intercomassets.com, *.intercom-messenger.com, intercom-sheets.com

  • Performance monitoring (Datadog): browser-intake-us3-datadoghq.com, *.browser-intake-us3-datadoghq.com

  • Digital twins (Matterport): static.matterport.com, *.matterport.com

Optional, for specific features

Allow these if your teams use the feature.

  • Maps: maps.googleapis.com, maps.gstatic.com

  • Sign-in protection (reCAPTCHA): www.google.com/recaptcha/, www.gstatic.com/recaptcha/, recaptcha.google.com

  • Reports (Power BI): app.powerbi.com, api.powerbi.com, *.powerbi.com, *.analysis.windows.net, login.microsoftonline.com

  • Fonts and script libraries: fonts.googleapis.com, fonts.gstatic.com, cdn.jsdelivr.net, code.jquery.com

  • Status page subscriptions: *.statuspage.io

Mobile apps (iOS and Android)

  • Mobile API: api-internal-prod2.redlist.software

  • Files and photos: blob.prod.redlist.software, redlistv2.blob.core.windows.net

  • Offline data: datalake.prod.redlist.software, redlistdl.blob.core.windows.net

  • Notifications: redlist-nhn-prod.servicebus.windows.net

  • Crash reports and analytics: browser-intake-us3-datadoghq.com, app-measurement.com, *.google-analytics.com, crashlyticsreports-pa.googleapis.com, *.crashlytics.com, *.googleapis.com

  • In-app support chat (Intercom): *.intercom.io

  • Digital twins (Matterport): my.matterport.com, cdn-2.matterport.com, static.matterport.com, events.matterport.com, authn.matterport.com

Android only

Android notifications also use Firebase Cloud Messaging: redlist-push-notifications.firebaseio.com, redlist-push-notifications.appspot.com, *.apps.googleusercontent.com (Firebase sign-in), *.googleapis.com and *.google.com. See Google's firewall guidance for Firebase.

Email

  • Sending domain: app.getredlist.com

  • Sender addresses: no-reply@app.getredlist.com, notification@app.getredlist.com

Allow by sending domain rather than IP address. Redlist mail is signed (SPF and DKIM) for app.getredlist.com, and the sending IP addresses can change.

Developers and integrations

  • REST and GraphQL API: api.yourredlist.com

  • AI assistants (MCP): mcp.yourredlist.com

  • Developer portal: developer.getredlist.com

Webhooks are sent from Redlist's cloud servers, whose IP addresses can change, so don't allow them by IP. Check the custom header you set when subscribing instead; see Webhooks.

No longer needed

Redlist no longer uses these, so you can remove them from your allow list: api.feedback.us.pendo.io, data.pendo.io (Pendo), *.appcenter.ms, in.appcenter.ms, api.mobile.azure.com (Microsoft App Center).

Something blocked that isn't listed? Contact support.

← Previous: Connect AI assistants