Skip to main content
Which addresses you need depends on the direction of the traffic.

GrowthBook Cloud connecting to you

GrowthBook Cloud makes outbound connections to your systems when it queries your data warehouse, sends event webhooks and SDK webhooks, and fetches from any other endpoint you configure. All of that traffic leaves from a single static address: It is a static NAT gateway address, unchanged since 2020, so it is safe to put in a firewall allowlist. If we ever need to change or add to it, we will announce it in advance. If you see connections from other addresses claiming to be GrowthBook, they are not us — contact support@growthbook.io.

You connecting to GrowthBook Cloud

Do not pin the addresses behind app.growthbook.io, api.growthbook.io, or cdn.growthbook.io in an allowlist. They are load balancer and CDN addresses that our providers can change without notice, and an allowlist built from them will break.
Allow the hostnames instead, and let DNS resolve them at connection time: If your egress firewall cannot allow hostnames, contact support@growthbook.io and we will work out an arrangement with you rather than have you guess at addresses.

Event Forwarder connections to your warehouse

The Event Forwarder reaches your warehouse from two places, and a warehouse network policy has to admit both: The streaming half runs on Confluent Cloud rather than on our own infrastructure, so it does not come from our NAT address. Allow the full list for your Event Forwarder’s Data Region — any address in it can be the one that connects, so a partial list produces intermittent failures that look like the connector working and then breaking.
Unlike our NAT address, this set is Confluent’s rather than ours, and Confluent notes that a major upgrade to their platform can change it. Check this page when you next revisit your network policy, and contact support@growthbook.io if the forwarder starts failing to connect. Last verified: September 16, 2026.

Self-hosted license verification

Self-hosted installs with a Pro or Enterprise license verify it against central-license-server.growthbook.io. That runs behind AWS Global Accelerator, which serves two static anycast addresses. Traffic can use either one, so allow both: Allowing only one of the two causes license checks to fail intermittently. If outbound access is not an option at all, contact sales@growthbook.io for an air-gapped license.