Configuring the firewall for Test Cloud
For general network configuration and firewall information, refer to Configuring the firewall
Outbound IP ranges update
As of April 27, 2026, the outbound IP range updates are complete for the following services:
- Apps
- Automation Ops
- AI Trust Layer, specifically the Bring your own LLM capability
- Integration Service
- Test Manager
For these services, the Deprecated Outbound IP ranges column in their respective sections below lists the IP ranges that are no longer active.
What you need to do: Remove those ranges from your firewall configuration. The Current Outbound IP ranges column lists the only active IP ranges you need to keep allowed.
Exception – Test Cloud Portal: The outbound IP range transition for Test Cloud Portal, specifically for outbound IP ranges used for Customer-Managed Keys (CMK), is still ongoing. Current and upcoming outbound IP ranges will coexist until approximately June 2026. Ensure that both the current and upcoming outbound IP ranges are allowed in your firewall configuration during this coexistence period.
Test Cloud Portal
Allow these domains used by Test Cloud Portal:
If you use Azure buckets, they must not be located in the tenant's region or in the failover region.
Domains
| Scenario | Domains |
|---|---|
| Sign in with basic authentication | https://account.uipath.comhttps://cloud.uipath.comhttps://platform-cdn.uipath.com |
| Sign in with Microsoft | https://aadcdn.msftauth.nethttps://account.uipath.comhttps://cloud.uipath.comhttps://login.live.comhttps://login.microsoftonline.comhttps://platform-cdn.uipath.com |
| Sign in with Google | https://account.uipath.comhttps://cloud.uipath.comhttps://accounts.google.comhttps://google.comhttps://lh3.googleusercontent.comhttps://platform-cdn.uipath.comhttps://www.gstatic.com |
| Sign in with LinkedIn | https://account.uipath.comhttps://cloud.uipath.comhttps://lnkd.demdex.nethttps://platform-cdn.uipath.comhttps://platform.linkedin.comhttps://static-exp1.licdn.comhttps://www.linkedin.com |
| Sign in with Azure Active Directory (Azure AD) | https://aadcdn.msftauth.nethttps://cloud.uipath.comhttps://login.microsoftonline.com |
| Sign in with UiPath Assistant (basic email) | *-signalr.service.signalr.net For events related to signing in with basic authentication: https://account.uipath.comhttps://cloud.uipath.comhttps://platform-cdn.uipath.com |
| Sign in with UiPath Studio (basic email) | https://api.nuget.org*-signalr.service.signalr.nethttps://gallery.uipath.comhttps://pkgs.dev.azure.com For events related to signing in with basic authentication: https://account.uipath.comhttps://cloud.uipath.comhttps://platform-cdn.uipath.com |
| Sign in for the first time / Reset password | uipath.eu.auth0.comaccount.uipath.com |
| Static assets: Fonts, Styling and CDN hosted scripts | Fonts: https://use.typekit.nethttps://fonts.gstatic.comhttps://platform-cdn.uipath.comImages: https://s.gravatar.comhttps://secure.gravatar.comhttps://*.wp.comhttps://*.googleusercontent.comhttps://i.ytimg.comhttps://platform-cdn.uipath.comCSS: https://fonts.googleapis.com/csshttps://use.typekit.nethttps://p.typekit.nethttps://platform-cdn.uipath.comScripts: https://primer.typekit.nethttps://use.typekit.nethttps://platform-cdn.uipath.com |
| Sign in via Auth0 (for EU) | uipath.eu.auth0.com |
| Update services | ctldl.windowsupdate.com To configure network connections, use Microsoft documentation. |
| Download Autopilot for Everyone from the AI Trust Layer admin section | https://autopilot-prd.azureedge.net |
Outbound IP ranges to enable a firewall for the customer-managed key
Required only when the Test Cloud Portal must connect to your Azure Key Vault for Customer-Managed Key (CMK) scenarios. These outbound IP ranges represent the source IP ranges that your firewall must allow. For details, refer to the Enabling the firewall for the customer-managed key documentation.
The outbound IP ranges used by Test Cloud Portal to enable a firewall for the customer-managed key are undergoing a phased update. For this service, current and upcoming outbound IP ranges will coexist until at least June 2026. The replacement of current IP ranges with the upcoming ones will begin approximately after June 2026.
To prevent service disruption, ensure that both the current and the upcoming outbound IP ranges are allowed in your firewall configuration. If either set of IP ranges is not allowed, CMK-related functionality may fail and result in errors.
Allow these outbound IP ranges through your firewall:
We recommend allowing all outbound IP ranges listed in the following table through your firewall.
| Regions | Current outbound IP ranges | Upcoming outbound IP ranges |
|---|---|---|
| Australia | |
|
| Canada | |
|
| Community | |
|
| European Union | |
|
| European Union (delayed) | |
|
| India | |
|
| Japan | |
|
| Singapore | |
|
| United Kingdom | |
|
| United States | |
|
| United States (delayed) | |
|
| Switzerland | |
|
| United Arab Emirates | |
|
Outbound IPs for notifications
You can configure Notification service systems to use SMTP servers from your own on-premises or cloud networks. If you want to provide additional security to your Notification service system, you can protect it with a firewall, and only allow Notification Service's outbound static IP ranges through it.
20.213.69.140/30
20.92.42.116/30
20.220.159.8/30
20.104.134.160/30
20.239.121.152/30
20.232.224.12/30
20.78.114.120/30
104.215.9.124/30
20.166.153.132/30
20.198.150.140/30
20.23.210.168/30
20.66.65.144/30
149.72.70.144
20.214.146.112/30
52.141.21.12/30
Relay
Allow these domains used by the Relay client to establish connectivity to Test Cloud:
| Purpose | Domains | Protocol | Port |
|---|---|---|---|
| Authentication and relay registration | cloud.uipath.com | HTTPS | 443 |
| Relay server - US region | us-relay.uipath.com | TCP (TLS passthrough required) | 443 |
| Relay server - EU region | eu-relay.uipath.com | TCP (TLS passthrough required) | 443 |
| Relay server - Canada region | ca-relay.uipath.com | TCP (TLS passthrough required) | 443 |
| Relay server - Switzerland region | ch-relay.uipath.com | TCP (TLS passthrough required) | 443 |
| Relay server - Australia region | au-relay.uipath.com | TCP (TLS passthrough required) | 443 |
| Relay server - Singapore region | sg-relay.uipath.com | TCP (TLS passthrough required) | 443 |
| Relay server - Japan region | jp-relay.uipath.com | TCP (TLS passthrough required) | 443 |
| Relay server - South Korea region | kr-relay.uipath.com | TCP (TLS passthrough required) | 443 |
| Relay server - UAE region | ae-relay.uipath.com | TCP (TLS passthrough required) | 443 |
| Relay server - UK region | uk-relay.uipath.com | TCP (TLS passthrough required) | 443 |
Action Center
Domains
The following table lists the domains used by Action Center that we recommend allowing, based on the functionality you plan to use:
| Scenario | Domains to Allow |
|---|---|
| Authentication | https://cloud.uipath.comhttps://account.uipath.com/https://lh3.googleusercontent.com/ |
| Navigate to Action Center page | https://cloud.uipath.comhttps://uipath-acc-prod.azureedge.net/https://www.youtube.com/https://platform-cdn.uipath.com/https://fonts.gstatic.com/*.googleapis.com |
| View/Assign/Un-assign/Delete an Action | https://cloud.uipath.comhttps://api.smartling.com/https://uipath-acc-prod.azureedge.net/*.cloudfront.nethttps://platform-cdn.uipath.com/https://fonts.gstatic.com/*.googleapis.com |
| Storage bucket (File upload/download) | *.blob.core.windows.net |
AI Center
Domains
The following table lists the domains used by AI Center:
| Module or Scenario |
Domains to Allow |
|---|---|
| AI Center |
|
| Identity Server |
|
| PkgManager |
|
| Deployer |
|
| Helper |
|
| Trainer |
|
| AppManager |
|
| Upload files |
Australia: https://aifproddataauetraining.blob.core.windows.net Canada: https://aifproddatacactraining.blob.core.windows.net Europe: https://aifproddatawetraining.blob.core.windows.net Japan: https://aifproddatajaetraining.blob.core.windows.net Singapore: https://aifproddataseatraining.blob.core.windows.net USA: https://aifproddataeustraining.blob.core.windows.net GXP: https://aifgxpdatawetraining.blob.core.windows.net |
| Third-party Services |
|
| AppInsights |
|
| Static Assets |
|
| Navigate to AI Center |
|
| Permissions |
|
| OpenId configuration |
|
AI Computer Vision
The following table lists the endpoint values and server locations used by AI Computer Vision:
The following table lists the endpoint values and server locations used by AI Computer Vision:
| Endpoint Value | Server Location |
|---|---|
https://cv.uipath.com | Nearest geolocation based on the request IP |
https://cv-eu.uipath.com | West Europe |
https://cv-us.uipath.com | US |
https://cv-delayed.uipath.com | Delayed enterprise ring deployment, located in the United States |
AI Trust Layer – Bring your own LLM
Outbound IP ranges
Allow the following outbound IP ranges to establish communication between the Bring your own LLM functionality of AI Trust Layer, and your own system. The IP ranges in the Deprecated Outbound IP ranges column are no longer active. Remove them from your firewall configuration.
The Bring your own LLM functionality depends on Integration Service connectors for communication. To use this capability and create connections successfully, you must also add the Integration Service outbound IP ranges to your allowlist.
Table 1. Outbound IP ranges for Bring your own LLM
| Region | Deprecated Outbound IP ranges | Current Outbound IP ranges |
|---|---|---|
| Australia | |
|
| Canada | |
|
| Europe (European Union) | |
|
| European Union delayed | |
|
| Community (Europe) | |
|
| India | |
|
| Japan | |
|
| Singapore | |
|
| United Kingdom | |
|
| United States | |
|
| United States delayed | |
|
Apps
Domains
The following table lists the domains used by Apps that you need to allow:
| Scenario | Domains to Allow |
|---|---|
| Navigate to Apps | https://cloud.uipath.comhttps://fonts.googleapis.comhttps://cdnjs.cloudflare.comhttps://uipath-apps-prd.azureedge.nethttps://fonts.gstatic.comhttps://dc.services.visualstudio.comhttps://<orgname>.uipath.host |
| Create apps, or create apps via import, or add or delete process | https://cloud.uipath.comhttps://uipath-apps-prd.azureedge.net |
| Export, clone, share, delete, edit, or publish an app | https://cloud.uipath.com |
| Run or preview an app | https://cloud.uipath.comhttps://fonts.googleapis.comhttps://cdnjs.cloudflare.comhttps://uipath-apps-prd.azureedge.nethttps://fonts.gstatic.comhttps://dc.services.visualstudio.comhttps://<orgname>.uipath.hosthttps://api.uipath.com |
| Select on Processes or Create rule | https://uipath-apps-prd.azureedge.net |
| Bind process | https://uipath-apps-prd.azureedge.nethttps://cloud.uipath.comhttps://dc.services.visualstudio.com |
| General or Permission | https://api.smartling.com |
| Create or delete a page, or create or delete History | https://cloud.uipath.comhttps://api.smartling.com |
| Connect to Apps | *.trafficmanager.netwss://*.uipath.systemswss://cloud.uipath.com |
Outbound IP ranges
The Apps service uses the outgoing IP ranges listed below for all external communications. The following table shows the available outbound IP ranges for each region.
The IP ranges in the Deprecated Outbound IP ranges column are no longer active. Remove them from your firewall configuration.
| Region | Deprecated Outbound IP ranges | Current Outbound IP ranges |
|---|---|---|
| Europe | 20.93.15.208 |
|
| Europe (Secondary) | 20.13.60.212 |
|
| Europe - Community | 4.207.32.162 |
|
| Europe - Community (Secondary) | 20.13.110.150 |
|
| US | 20.121.170.55 |
|
| US (Secondary) | 20.72.203.238 |
|
| Canada | 20.200.104.214 |
|
| Canada (Secondary) | 20.220.98.56 |
|
| Singapore | 20.44.206.197 |
|
| Japan | 20.89.117.202 |
|
| Japan (Secondary) | 104.46.238.159 |
|
| Australia | 20.167.34.255 |
|
| Australia (Secondary) | 20.11.199.185 |
|
| India | 4.224.9.5 |
|
| India (Secondary) | 13.71.90.136 |
|
| UK | 172.165.145.81 |
|
| UK (Secondary) | 51.141.6.153 |
|
| GXP US (Secondary) | 52.143.81.192 |
|
| GXP US | 20.246.192.220 |
|
| Switzerland | |
|
| United Arab Emirates | |
|
| South Korea | N/A | |
Traffic from this IPs needs to be allowed through the Organization DMZ firewall and any other intermediate firewalls including the firewall on the computer/s in which Orchestrator application is hosted.
- The associated port on which Orchestrator application is hosted needs to be exposed through the DMZ on all relevant firewalls (see the previous point).
- An Orchestrator user who has read and execute access to relevant processes whose credential will be used from UiPath Apps to talk to Orchestrator.
- If using local robot process execution through RobotJS, please ensure RobotJS is properly configured using instructions provided at RobotJS.
Best practices
- Ensure that the On-Premise hosted Orchestrator is only accessible through a secure HTTPS channel.
- Create a low privilege user in Orchestrator that only has read and execute access to just the desired processes/folders and use that for the integration.
CORS policy requirements for Storage Buckets
When using storage buckets from an on-premises or hybrid Orchestrator, add https://cloud.uipath.com to the acceptedRootURLs list in the UiPath.Orchestrator.dll.config file.
- If your Orchestrator instance is hosted in Test Cloud, this configuration is already in place.
- For external buckets, configure the allowed origins as described in the CORS and CSP configuration guide."
UiPath Apps uploads and downloads files using the SAS URL generated by Orchestrator when interacting with storage buckets hosted in an on-premises environment. End users must have the appropriate permissions granted through that SAS URL to perform both upload and download operations.
All access control is defined and enforced by the underlying storage account configuration. UiPath does not manage or override these permissions.
If users encounter errors when uploading or downloading files through UiPath Apps, the storage account's SAS policies or access restrictions should be reviewed and updated by the storage owner to ensure the required level of access.
Content types to add to the allow list
UiPath Apps utilizes the content types application/octet-stream and application/zip for downloading specific DLL files required to run and preview created applications. It is important to ensure the following content types are allowed within your network settings to avoid interruptions in app functionality:
application/zip
application/octet-stream
application/json
text/html
application/javascript
text/css
font/woff2
image/vnd.microsoft.icon
image/svg+xml
image/bmp
image/jpeg
image/png
image/gif
Key Considerations
Apps are developed using Blazor technology, which processes assemblies directly in the browser. If restrictions for the required content types cannot be lifted within your network, Apps may not function as expected, as there are currently no alternative solutions to bypass these limitations.
Apps in Studio Web as an alternative
Apps in Studio Web are designed with a different architecture, that does not require downloading DLL files. If network restrictions prevent the use of Standalone Apps, consider adopting Apps in Studio Web (RPA Apps). This architecture eliminates dependency on restricted content types, ensuring smoother compatibility in restricted network environments.
Automation Cloud Robots - Serverless
Outbound IP ranges
Outbound IP ranges for Automation Cloud Robots - Serverless enable you to route outbound network traffic through a dedicated, static IP address ranges managed by UiPath. This allows you to whitelist or securely integrate with external systems that restrict incoming connections to known IPs.
Configuration
You can enable static outbound IP ranges while creating the Serverless template and going to the Network Configuration page.
Availability
The outbound IP ranges can sometimes change as a result of infrastructure deployments. To help keep you on top of any changes, we have compiled a list of up-to-date static outbound IP ranges, in the following tables.
Community Users
| Region | CIDR | Outbound IP ranges |
|---|---|---|
| Europe | |
|
Enterprise Users
| Region | CIDR | Outbound IP ranges |
|---|---|---|
| Australia | |
|
| United States | |
|
| Japan | |
|
| Europe (European Union) | |
|
- Added on February 18th, 2026.
Automation Hub
Domains
The following table lists the domains used by Automation Hub:
The following table lists the domains used by Automation Hub:
| Scenario | Domains to Allow |
|---|---|
| Navigate to the Automation Hub page | https://cloud.uipath.comhttp://*.userpilot.iohttps://dc.services.visualstudio.comhttps://ah-prod-ts-blue-eu.uipath.comhttps://ah-prod-ts-blue-us.uipath.comhttps://ah-prod-ts-blue-ja.uipath.comhttps://ah-prod-ts-blue-au.uipath.comhttps://ah-prod-ts-blue-ca.uipath.comhttps://ah-prod-ts-blue-sea.uipath.comhttps://ah-prod-ts-blue-uk.uipath.comhttps://ah-prod-ts-blue-in.uipath.comhttps://ah-gxp-ts-blue-us.uipath.com |
| Use OpenAPI for Automation Hub | https://automation-hub.uipath.comhttp://ah-gxp-openapi-us.uipath.com |
Automation Ops
Domains
The following table lists the domains used by Automation Ops:
| Scenario | Domains to Allow |
|---|---|
| Navigate to the Automation Ops page | https://stdadmstgcdn.azureedge.nethttps://app.vssps.visualstudio.comhttps://stdadmstgcdn.blob.core.windows.nethttps://nexus.ensighten.comhttps://cloud.uipath.comhttps://platform-cdn.uipath.comhttps://use.typekit.nethttps://p.typekit.nethttps://content.usage.uipath.comhttps://dc.services.visualstudio.comhttps://data.usage.uipath.com*-signalr.service.signalr.nethttps://s.gravatar.comhttps://i2.wp.comhttps://github.comhttps://github.githubassets.comhttps://avatars.githubusercontent.comhttps://collector.github.comhttps://api.github.com |
Outbound IP ranges
The table below lists all outbound IP ranges currently used by Automation Ops. The IP ranges in the Deprecated Outbound IP ranges column are no longer active. Remove them from your firewall configuration.
| Region | Deprecated Outbound IP ranges | Current Outbound IP ranges |
|---|---|---|
| Australia | |
|
| Japan | |
|
| United States | |
|
| United States GXP | |
|
| Europe | |
|
| Europe GXP | |
|
| Canada | |
|
| Singapore | |
|
| India | |
|
| UK | |
|
| Switzerland | |
|
| United Arab Emirates | |
|
| South Korea | N/A | |
IXP
Domains
The following table lists the domains that IXP uses:
| Scenario | Domains to Allow |
|---|---|
| Admin Portal / Identity Server | https://cloud.uipath.com |
| Static assets | https://fonts.googleapis.comhttps://fonts.gstatic.com |
| Azure SignalR | *.service.signalr.net |
| Telemetry | https://*.in.applicationinsights.azure.comhttps://dc.services.visualstudio.com |
| Pendo (clickable in-app guides) | https://*.pendo.io |
| Performance monitoring | https://o486811.ingest.sentry.io |
Inbound IP ranges
This section applies only to legacy Re:infer customers.
Add the following inbound IP ranges to your allow list to use IXP and create connections:
| Region | Inbound IP ranges |
|---|---|
| Europe | 34.91.100.206 |
| US | |
| Japan | 34.84.144.176 |
| Australia | 35.189.46.91 |
| Canada | 34.152.10.176 |
| Singapore | 35.240.179.214 |
Outbound IP ranges
Allow the following outbound IP ranges for IXP to sync emails from your Exchange. For details, check the Overview Exchange integration.
| Region | Outbound IP ranges |
|---|---|
| Europe | 35.204.220.118 |
| US | 34.71.173.219 |
| Japan | 34.84.107.92 |
| Australia | 34.87.223.173 |
| Canada | 34.152.42.160 |
| Singapore | 34.143.128.81 |
Data Fabric
Domains
The following table lists the domains used by Data Fabric:
| Scenario | Domains to Allow |
|---|---|
| All Data Fabric operations | https://cloud.uipath.com |
| Fetching static frontend content | *.cloudapp.azure.com |
| Sending notifications to notification hub | *.service.signalr.net |
| Collection of telemetry | *.visualstudio.com |
Document Understanding
Domains
The following table lists the domains used by Document Understanding:
| Module or Scenario | Domains to Allow |
|---|---|
| Navigate to Document Understanding | https://*.uipath.com |
| Azure | https://*.azure.com |
| Network | https://*.azureedge.nethttps://*.azurefd.net |
| Telemetry | https://*.visualstudio.com |
| Azure SignalR | https://*.service.signalr.net |
| Storage | https://*.trafficmanager.nethttps://*.blob.core.windows.net |
| Pendo | https://*.pendo.io |
| Public endpoints | Check the Public endpoints page for the full list of public endpoints URLs. |
Insights
Domains
The following table lists the domains used by Insights:
| Scenario | Domains to Allow |
|---|---|
| Navigate to the Insights page | https://cloud.uipath.comhttps://*.lookercdn.comhttps://uipath-insights-statics.azureedge.net/https://*.looker.uipath.com/ |
Outbound IP ranges
Outbound IP ranges allow you to add a list of IPs for Log Export and Real Time Data Export features to the allowlist and not open your network to all external IPs. If the Blob storage regions correspond to the respective Insights service region, you cannot use public IPs.
| Insights service region | Blob storage region | Functionality | Outbound static IP ranges |
|---|---|---|---|
| Europe |
|
Log Export | |
| Real Time Data Export | |
||
| Looker SFTP notifications | |
||
| United States of America |
|
Log Export | |
| Real Time Data Export | |
||
| Looker SFTP notifications | |
||
| Australia |
|
Log Export | |
| Real Time Data Export | |
||
| Looker SFTP notifications | |
||
| Japan |
|
Log Export | |
| Real Time Data Export | |
||
| Looker SFTP notifications | |
||
| Canada |
|
Log Export | |
| Real Time Data Export | |
||
| Looker SFTP notifications | |
||
| Singapore |
|
Log Export | |
| Real Time Data Export | |
||
| Looker SFTP notifications | |
||
| India |
|
Log Export | |
| Real Time Data Export | |
||
| Looker SFTP notifications | |
||
| United Kingdom |
|
Log Export | |
| Real Time Data Export | |
||
| Looker SFTP notifications | |
||
| GXP United States of America |
|
Log Export | 134.33.240.104 |
| Real Time Data Export | |
||
| Looker SFTP notifications | |
||
| GXP Europe |
|
Log Export | |
| Real Time Data Export | |
||
| Looker SFTP notifications | |
||
| Switzerland |
|
Log Export | |
| Real Time Data Export | |
||
| United Arab Emirates |
|
Log Export | |
| Real Time Data Export | |
||
| South Korea |
|
Log Export | |
| Real Time Data Export | |
Limitations
For Log Export, Google Storage does not support inbound IP restriction.
Due to a limitation on Microsoft side for Log Export, you cannot set up inbound IP restriction when your Azure blob storage account and the Insights infrastructure is under the same region in Azure. Because of this, you cannot use the following regions for blob storage account based on the Insights service region:
- Insights US: North Europe, East US
- Insights Europe: North Europe, West Europe (For Community Licensing)
- Insights UK: North Europe, UK South
- Insights Canada: North Europe, Canada Central
- Insights Singapore: North Europe, Southeast Asia
- Insights India: North Europe, Central India
- Insights Australia: North Europe, Australia East
- Insights Japan: North Europe, Japan East
- Insights GXP Europe: North Europe, East US
- Insights GXP US: East US
For more information on this limitation, check the Restrictions for IP network rules page from the Microsoft Azure Blob Storage documentation.
Integration Service
Outbound IP ranges
Add the following outbound IP ranges to your allow list to use Integration Service and create connections, as described in the following table.
The IP ranges in the Deprecated Outbound IP ranges column are no longer active. Remove them from your firewall configuration.
| Region | Deprecated Outbound IP ranges | Current Outbound IP ranges | Environment |
|---|---|---|---|
| Australia | |
|
Production |
| Canada | |
|
Production |
| Europe | |
|
Production |
| Japan | |
|
Production |
| India | |
|
Production |
| Singapore | 20.44.206.197 |
|
Production |
| Switzerland | |
|
Production |
| United Arab Emirates | |
|
Production |
| South Korea | N/A | |
Production |
| United Kingdom | |
|
Production |
| United States | |
|
Production |
| GxP United States (Delayed update organizations) | |
|
Production |
| Community | |
|
Production |
IP addresses marked with an asterisk () are designated for newly incorporated Azure regions. These IPs will supersede the existing regional IPs upon completion of the scheduled tenant migration process. For details, refer to the Integration Service release notes.
Orchestrator
Domains
Robots send traffic to these Test Cloud Orchestrator domains. We recommend that you allow these domains to ensure proper functioning of your automations, as described in the following table:
Robots send traffic to these Test Cloud Orchestrator domains. We recommend that you allow these domains to ensure proper functioning of your automations, as described in the following table:
| Module or Functionality | Domains to Allow |
|---|---|
| UiPath Orchestrator | https://cloud.uipath.comhttps://orch-cdn.uipath.comhttps://account.uipath.com |
| Automation Cloud Robots - VM | https://cloud.uipath.comhttps://download.uipath.com |
| Storage | *.blob.core.windows.net If using Amazon s3 buckets: *.s3.amazonaws.com |
| Package and library feeds (library, tenant processes, and others) | https://pkgs.dev.azure.com |
| Azure SignalR | *.service.signalr.net |
| Studio and Robot auto-update functionality | https://download.uipath.com |
| Traffic Manager (internal) | *.trafficmanager.net |
Outbound IP ranges
We recommend allowing these outbound IP ranges, which send traffic from Orchestrator towards your resources. For details, refer to Orchestrator outbound IP ranges.
Community users
| Region | CIDR | Outbound IP ranges |
|---|---|---|
| Europe (European Union) | |
|
Enterprise users
| Region | CIDR | Outbound IP ranges |
|---|---|---|
| Australia | |
|
| Canada | |
|
| United States | |
|
| Japan | |
|
| Europe (European Union) | |
|
| Singapore | |
|
| United Kingdom | |
|
| India | |
|
| Switzerland | |
|
| United Arab Emirates | |
|
| South Korea | |
|
Delayed update organizations
| Region | CIDR | Outbound IP ranges |
|---|---|---|
| Europe (European Union) | |
|
| United States | |
|
MCP Servers
The remote MCP Servers service uses the outgoing IP ranges listed below for all external communications. The following table shows the available outbound IP ranges for each region.
| Region | Outbound IP ranges |
|---|---|
| Europe | |
| Europe (Secondary) | |
| Europe - Community | |
| Europe - Community (Secondary) | |
| US | |
| US (Secondary) | |
| Canada | |
| Canada (Secondary) | |
| Singapore | |
| Japan | |
| Japan (Secondary) | |
| Australia | |
| Australia (Secondary) | |
| India | |
| India (Secondary) | |
| UK | |
| UK (Secondary) | |
| GXP Europe | |
| GXP Europe (Secondary) | |
| GXP US | |
| GXP US (Secondary) | |
Process Mining
Domains
The following table lists the domains used by Process Mining:
| Module or Scenario | Domains to Allow |
|---|---|
| Identity Server | https://cloud.uipath.com |
| Static assets | https://fonts.googleapis.comhttps://fonts.gstatic.comhttps://content.usage.uipath.comhttps://s.gravatar.comhttps://i1.wp.com |
| Azure SignalR | *.service.signalr.net |
| Telemetry | https://*.in.applicationinsights.azure.com |
| Upload files | *.blob.core.windows.net |
Solutions
Domains
The following table lists the domains used by Solutions:
| Scenario | Domains to Allow |
|---|---|
| Navigate to the Solutions Management page | https://cloud.uipath.comhttps://fonts.googleapis.comhttps://fonts.gstatic.comhttps://dc.services.visualstudio.comapi.smartling.comuse.typekit.netp.typekit.nets.gravatar.comi2.wp.comhttps://platform-cdn.uipath.comhttps://sol-cdn.uipath.comhttps://solutions.uipath.com |
| Storage | *.blob.core.windows.net |
| Azure SignalR | *.service.signalr.net |
Studio Web
Domains
The following table lists the domains used by Studio Web:
| Module or Functionality | Domains to Allow |
|---|---|
| Azure SignalR | wss://*.service.signalr.nethttps://*.service.signalr.netwss://*.trafficmanager.net |
| UiPath products | https://*.uipath.com |
| UiPath products (in-app feedback) | https://studio-feedback.azure-api.net |
| UiPath products (static assets) | https://platform-cdn.uipath.comhttps://content.usage.uipath.comhttps://fonts.gstatic.comhttps://d2c7xlmseob604.cloudfront.nethttps://fonts.googleapis.com/https://*.typekit.nethttps://fonts.gstatic.comhttps://s.gravatar.comhttps://secure.gravatar.comhttps://*.wp.comhttps://*.googleusercontent.comhttps://i.ytimg.com |
| UiPath products (telemetry) | https://data.usage.uipath.com |
| Third-party services (clickable guides) | https://*.pendo.io |
| Third-party services (storage) | https://*.blob.core.windows.nethttps://*.amazonaws.com |
| Third-party services (telemetry) | https://dc.services.visualstudio.com |
| Third-party services (translations helper) | https://api.smartling.com |
Task Mining
Domains
If your company uses proxies, the URLs, described in the following table, need to be added to the Firewall Exceptions so the Task Mining desktop components connect to our web servers.
The Task Mining Desktop application uses web sockets for real-time communication with the server (telemetry and governance). For the URLs and IPs to be allowed, the transparent proxy is expected to have the HTTPS and WSS protocols enabled.
| Component | URL | Port |
|---|---|---|
| Admin Portal | https://cloud.uipath.com |
443 |
| Web Portal | *.blob.core.windows.net |
443 |
| Pendo | https://content.usage.uipath.com |
443 |
| Azure App Insights |
|
443 |
| Azure Signalr |
|
443 |
| Avatars | i2.wp.com/cdn.auth0.com/avatars |
443 |
Test Manager
This section lists the domains used by Test Manager and the outbound IP ranges that you should consider allowing if you want to use various Test Manager capabilities.
Domains
The following table lists the domains used by Test Manager that we recommend allowing, based on the functionality you plan to use:
| Module or functionality | Domains to allow |
|---|---|
| UiPath Test Manager | https://cloud.uipath.com |
| Azure SignalR | *.service.signalr.net |
SAP Heatmap and CIA RFC Outbound IPs
Allow the following outbound IP ranges to establish communication between UiPath Test Manager and your SAP system via an RFC connection. The following table shows the available outbound IP ranges for each region. The IP ranges in the Deprecated Outbound IP ranges column are no longer active. Remove them from your firewall configuration.
| Region | Deprecated Outbound IP ranges | Current Outbound IP ranges |
|---|---|---|
| Australia | |
|
| Canada | |
|
| Europe (European Union) | |
|
| India | |
|
| GXP United States | |
|
| Japan | |
|
| Singapore | 20.44.206.197/32 |
|
| United Kingdom | |
|
| United States | |
|
| Switzerland | |
|
| United Arab Emirates | |
|
| South Korea | N/A | |
SAP Heatmap and CIA Web Service Outbound IPs
Allow the following static outbound IP ranges to enable the communication between UiPath Test Manager and your SAP system, via a web service connection.
Allow these outbound IP ranges through your firewall:
| Regions | Outbound IP ranges |
|---|---|
| Australia | |
| Canada | |
| Community | |
| European Union | |
| European Union (delayed) | |
| India | |
| Japan | |
| Singapore | |
| Switzerland | |
| United Arab Emirates | |
| South Korea | |
| United Kingdom | |
| United States | |
| United States (delayed) | |
Outbound IP ranges for connectors
If you enhance your system's security with a firewall, consider allowing only Test Manager outbound IP ranges for using out-of-the-box connectors.
The following outbound IP ranges apply to all supported regions, including: Australia, Canada, European Union, India, Japan, Singapore, United Kingdom, United States, and GxP United States (delayed).
Allow these outbound IP ranges through your firewall:
| Regions | Outbound IP ranges |
|---|---|
| Australia, Canada, European Union, India, Japan, Singapore, United Kingdom, United States, and GxP United States (delayed) | |
| Switzerland | |
| United Arab Emirates | |
| South Korea | |