Outbound IP addresses
Find the workspace's verified outbound IPv4 address for external firewall allowlists.
Some external databases and APIs allow traffic only from known public addresses. Openstead's dedicated outbound IP connection identifies the static IPv4 address used by your workspace runtime.
This is the source address of outbound requests. It is different from a custom domain that routes visitors into an application.
Configure an outbound IP connection
- Make sure the workspace has an active qualifying paid service.
- Open the workspace's Connections → Dedicated IPs area.
- Create the connection and describe the service you need to reach.
- Wait for its status to become active.
- Copy the verified address from the connection details into the external provider's allowlist.
The workspace runtime must be deployed before its outbound routing can be verified. A pending connection is not evidence that an address is ready to use.
Scope
The address is associated with the workspace runtime and shared by services in that workspace. It is not a unique address per application or per deployment.
Allowlist only the required destination ports and still use the external service's authentication. An IP allowlist is an additional access control, not a replacement for passwords, API keys, or TLS.
Operational changes
Use the currently active connection details as the authority. Review external allowlists after a networking change or workspace-runtime recovery. Do not hardcode an address copied from another workspace or from a documentation example.
If verification fails, check the connection's displayed message and contact support with its identifier and intended destination. Do not expose third-party access credentials in the description.
Troubleshooting an external connection
Confirm the external provider saved the IPv4 address, permits the destination port, and accepts credentials from this application. Run a connection attempt from the deployed application; a successful request from your laptop has a different source address and does not test the Openstead allowlist.