Skip to main content
Which addresses you need depends on the direction of the traffic.

GrowthBook Cloud connecting to you

GrowthBook Cloud makes outbound connections to your systems when it queries your data warehouse, sends event webhooks and SDK webhooks, and fetches from any other endpoint you configure. All of that traffic leaves from a single static address: It is a static NAT gateway address, unchanged since 2020, so it is safe to put in a firewall allowlist. If we ever need to change or add to it, we will announce it in advance. If you see connections from other addresses claiming to be GrowthBook, they are not us — contact support@growthbook.io.

You connecting to GrowthBook Cloud

Do not pin the addresses behind app.growthbook.io, api.growthbook.io, or cdn.growthbook.io in an allowlist. They are load balancer and CDN addresses that our providers can change without notice, and an allowlist built from them will break.
Allow the hostnames instead, and let DNS resolve them at connection time: If your egress firewall cannot allow hostnames, contact support@growthbook.io and we will work out an arrangement with you rather than have you guess at addresses.

Self-hosted license verification

Self-hosted installs with a Pro or Enterprise license verify it against central-license-server.growthbook.io. That runs behind AWS Global Accelerator, which serves two static anycast addresses. Traffic can use either one, so allow both: Allowing only one of the two causes license checks to fail intermittently. If outbound access is not an option at all, contact sales@growthbook.io for an air-gapped license.