GrowthBook Cloud connecting to you
GrowthBook Cloud makes outbound connections to your systems when it queries your data warehouse, sends event webhooks and SDK webhooks, and fetches from any other endpoint you configure. All of that traffic leaves from a single static address:
It is a static NAT gateway address, unchanged since 2020, so it is safe to put in a firewall allowlist. If we ever need to change or add to it, we will announce it in advance.
If you see connections from other addresses claiming to be GrowthBook, they are not us — contact support@growthbook.io.
You connecting to GrowthBook Cloud
Allow the hostnames instead, and let DNS resolve them at connection time:
If your egress firewall cannot allow hostnames, contact support@growthbook.io and we will work out an arrangement with you rather than have you guess at addresses.
Event Forwarder connections to your warehouse
The Event Forwarder reaches your warehouse from two places, and a warehouse network policy has to admit both:
The streaming half runs on Confluent Cloud rather than on our own infrastructure, so it does not come from our NAT address. Allow the full list for your Event Forwarder’s Data Region — any address in it can be the one that connects, so a partial list produces intermittent failures that look like the connector working and then breaking.
us-east-1 (27 addresses)
us-east-1 (27 addresses)
eu-west-1 (12 addresses)
eu-west-1 (12 addresses)
Self-hosted license verification
Self-hosted installs with a Pro or Enterprise license verify it againstcentral-license-server.growthbook.io. That runs behind AWS Global Accelerator, which serves two static anycast addresses. Traffic can use either one, so allow both:
Allowing only one of the two causes license checks to fail intermittently.
If outbound access is not an option at all, contact sales@growthbook.io for an air-gapped license.

