- Getting started
- Data security and compliance
- Data security and compliance
- Encryption
- Certificates
- Functional security
- Configuring the firewall for Test Cloud
- Legacy - Configuring the firewall for Test Cloud
- Configuring the firewall for Test Cloud Public Sector
- Configuring the firewall for Test Cloud Dedicated
- Feature rollout
- High availability and disaster recovery strategy
- Organizations
- Authentication and security
- Licensing
- About licensing
- Unified Pricing: Licensing plan framework
- Activating your Enterprise license
- Migrate from Test Suite to Test Cloud
- License migration
- Assigning licenses to tenants
- Assigning user licenses
- Deallocating user licenses
- Monitoring license allocation
- License overallocation
- Licensing notifications
- User license management
- Tenants and services
- Accounts and roles
- AI Trust Layer
- External applications
- Notifications
- Logging
- Data Export
- Testing in your organization
- Troubleshooting
- Migrating to Test Cloud
Legacy IP ranges for Test Cloud services, provided for reference during the transition to the unified IP range configuration.
For general network configuration and firewall information, refer to Configuring the firewall
Deprecation notice — action required
The IP ranges listed on this page are being deprecated. As of June 16, 2026, new unified IP ranges have been published and must be added to your allowlist alongside these ranges. Starting September 16, 2026, the IP ranges on this page will be gradually phased out. For specific dates, see the Timeline in the Deprecation notice section below.
Before the transition end date: Keep these IP ranges in your firewall configuration and add the new unified IP ranges. Both sets must be allowlisted simultaneously during the transition window.
After the transition end date: Continue allowlisting both the IP ranges on this page and the unified IP ranges until a subsequent release note confirms the legacy IP ranges can be safely removed.
Terminology update — July 31, 2026
We renamed "outbound IP ranges" to IP ranges throughout this page. "Outbound" described UiPath's side of the connection, not yours — these ranges are what UiPath connects from, but from your firewall's perspective this traffic is inbound. Fully qualified domain names (FQDNs) remain the outbound side, from your perspective.
Deprecation notice
The IP ranges on this page are being supplemented with a new unified set of IP ranges and will be gradually phased out starting September 16, 2026. This section summarizes the full timeline, scope, and required actions.
What is changing
UiPath is consolidating all service-specific IP ranges into a single set of unified IP ranges, organized by global customer region rather than by individual service. The new unified ranges apply uniformly to all services within each region.
Affected services: Test Cloud Portal, AI Trust Layer, Notification Service, Orchestrator, Test Manager, Apps, Automation Ops, and Integration Service.
Not affected (no changes to their IP ranges): Document Understanding, Insights, IXP, and Automation Cloud Robots - Serverless.
Timeline
| Milestone | Date |
|---|---|
| Unified IP ranges published; deprecation announced; dual-allowlist window begins | June 16, 2026 |
| Dual-allowlist window ends; legacy IP ranges begin phased-out | September 16, 2026 |
| This page no longer updated | September 16, 2026 |
What you need to do
- Add the unified IP ranges now. Visit the Configuring the firewall for Test Cloud page and add all ranges for your organization region and tenant region. Some UiPath service features inherit the organization's region rather than the tenant's region. If they differ, allowlist the IP ranges for both. For more information on organization-level and tenant-level services, see Global cloud regions. If your tenant or organization migrates to another region, update IP ranges accordingly.
- Before the transition end date (see Timeline): Keep the IP ranges on this page and the new unified IP ranges both allowlisted simultaneously.
- After the transition end date: Continue allowlisting both sets of IP ranges until a subsequent release note confirms the legacy IP ranges can be safely removed.
- Allow applicable regional domains. For domain entries grouped by region, allow the domains listed for the region where your service is deployed. If your organization uses more than one region, allow the domains for each applicable region.
Test Cloud Portal
Allow these domains used by Test Cloud Portal:
If you use Azure buckets, they must not be located in the tenant's region or in the failover region.
Domains
Allow the domains required for the sign-in method and portal functionality that your organization uses:
| Scenario or functionality | Domains to allow | Impact if blocked |
|---|---|---|
| Sign in with basic authentication | https://account.uipath.comhttps://cloud.uipath.comhttps://platform-cdn.uipath.com | Auth0 login through social providers or with an email address and password is unavailable. Single sign-on remains available. |
| Sign in with Microsoft | https://aadcdn.msftauth.nethttps://account.uipath.comhttps://cloud.uipath.comhttps://login.live.comhttps://login.microsoftonline.comhttps://platform-cdn.uipath.com | Microsoft consumer-account and Microsoft Entra ID sign-in are unavailable, and Microsoft authentication pages may not render. |
| Sign in with Google | https://account.uipath.comhttps://cloud.uipath.comhttps://accounts.google.comhttps://google.comhttps://lh3.googleusercontent.comhttps://platform-cdn.uipath.comhttps://www.gstatic.com | Google sign-in may fail. |
| Sign in with LinkedIn | https://account.uipath.comhttps://cloud.uipath.comhttps://lnkd.demdex.nethttps://platform-cdn.uipath.comhttps://platform.linkedin.comhttps://static-exp1.licdn.comhttps://www.linkedin.com | LinkedIn sign-in may fail. |
| Sign in with Azure Active Directory (Azure AD) | https://aadcdn.msftauth.nethttps://cloud.uipath.comhttps://login.microsoftonline.com | Microsoft sign-in pages may not render, and single sign-on through Microsoft Entra ID is unavailable. |
| Use third-party packages with on-premises Studio and Robots | https://api.nuget.org | Optional. Third-party .NET packages from NuGet are unavailable. |
| Use UiPath Marketplace community packages | https://gallery.uipath.com | Optional. Community packages from UiPath Marketplace are unavailable. |
| Sign in for the first time or reset a password | uipath.eu.auth0.comaccount.uipath.com | Auth0 password setup and self-service password reset are unavailable. |
| Load portal fonts, styling, scripts, and images | https://use.typekit.nethttps://fonts.gstatic.comhttps://platform-cdn.uipath.comhttps://s.gravatar.comhttps://secure.gravatar.comhttps://*.wp.comhttps://*.googleusercontent.comhttps://i.ytimg.comhttps://fonts.googleapis.com/csshttps://p.typekit.nethttps://primer.typekit.net | Fonts, icons, images, or styling may not render correctly. |
| Sign in through Auth0 in the European Union | uipath.eu.auth0.com | Auth0 sign-in and password-management flows are unavailable. |
| Download Autopilot for Everyone | https://autopilot-prd.azureedge.net | Autopilot for Everyone cannot be downloaded from the AI Trust Layer admin section. |
IP ranges to enable a firewall for the customer-managed key
Required only when the Test Cloud Portal must connect to your Azure Key Vault for Customer-Managed Key (CMK) scenarios. These IP ranges represent the source IP ranges that your firewall must allow. For details, refer to the Enabling the firewall for the customer-managed key documentation.
The planned migration of Test Cloud Portal CMK IP ranges to new ranges — previously tracked as a separate transition (see the April 27, 2026 IP ranges completion announcement) — has been paused. This migration is now absorbed into the broader unified IP ranges transition. The IP ranges listed below remain active until the transition end date shown in the Timeline.
Allow these IP ranges through your firewall:
| Regions | IP ranges |
|---|---|
| Australia | |
| Canada | |
| Community | |
| European Union | |
| European Union — delayed update (GxP) | |
| India | |
| Japan | |
| Singapore | |
| United Kingdom | |
| United States | |
| United States — delayed update (GxP) | |
IP ranges for notifications
You can configure Notification service systems to use SMTP servers from your own on-premises or cloud networks. If you want to provide additional security to your Notification service system, you can protect it with a firewall, and only allow Notification Service's static IP ranges through it.
20.213.69.140/30
20.92.42.116/30
20.220.159.8/30
20.104.134.160/30
20.239.121.152/30
20.232.224.12/30
20.78.114.120/30
104.215.9.124/30
20.166.153.132/30
20.198.150.140/30
20.23.210.168/30
20.66.65.144/30
149.72.70.144
20.213.69.140/30
20.92.42.116/30
20.220.159.8/30
20.104.134.160/30
20.239.121.152/30
20.232.224.12/30
20.78.114.120/30
104.215.9.124/30
20.166.153.132/30
20.198.150.140/30
20.23.210.168/30
20.66.65.144/30
149.72.70.144
Relay
Allow these domains used by the Relay client to establish connectivity to Test Cloud:
| Purpose | Domains | Protocol | Port |
|---|---|---|---|
| Authentication and relay registration | cloud.uipath.com | HTTPS | 443 |
| Relay server - US region | us-relay.uipath.com | TCP (TLS passthrough required) | 443 |
| Relay server - EU region | eu-relay.uipath.com | TCP (TLS passthrough required) | 443 |
| Relay server - Canada region | ca-relay.uipath.com | TCP (TLS passthrough required) | 443 |
| Relay server - Switzerland region | ch-relay.uipath.com | TCP (TLS passthrough required) | 443 |
| Relay server - Australia region | au-relay.uipath.com | TCP (TLS passthrough required) | 443 |
| Relay server - Singapore region | sg-relay.uipath.com | TCP (TLS passthrough required) | 443 |
| Relay server - Japan region | jp-relay.uipath.com | TCP (TLS passthrough required) | 443 |
| Relay server - South Korea region | kr-relay.uipath.com | TCP (TLS passthrough required) | 443 |
| Relay server - UAE region | ae-relay.uipath.com | TCP (TLS passthrough required) | 443 |
| Relay server - UK region | uk-relay.uipath.com | TCP (TLS passthrough required) | 443 |
Action Center
Domains
Allow the domains required for the Action Center functionality that your organization uses:
| Scenario or functionality | Domains to allow | Impact if blocked |
|---|---|---|
| Authenticate | https://cloud.uipath.comhttps://account.uipath.com | Action Center or basic authentication is unavailable. |
| Open Action Center | https://cloud.uipath.comhttps://uipath-acc-prod.azureedge.nethttps://www.youtube.comhttps://platform-cdn.uipath.comhttps://fonts.gstatic.com*.googleapis.com | Action Center or required frontend assets may be unavailable. If YouTube is blocked, only the introductory video is unavailable. |
| View, assign, unassign, or delete an action | https://cloud.uipath.comhttps://uipath-acc-prod.azureedge.nethttps://platform-cdn.uipath.comhttps://fonts.gstatic.com*.googleapis.com | Action Center or required frontend assets may be unavailable. |
| Upload or download files from storage buckets | *.blob.core.windows.net | Files in form and app actions do not render, and Document Understanding tasks do not work. |
AI Center
Domains
Allow the domains required for AI Center:
| Scenario or functionality | Domains to allow | Impact if blocked |
|---|---|---|
| Open AI Center and authenticate | https://cloud.uipath.com | AI Center is unavailable. |
| Load static assets | https://aifprodassets.azureedge.nethttps://i2.wp.com/cdn.auth0.comhttps://api.smartling.comhttps://s.gravatar.comhttps://js-agent.newrelic.comhttps://fonts.gstatic.comhttps://use.typekit.nethttps://fonts.googleapis.comhttps://d2c7xlmseob604.cloudfront.nethttps://du-prod-cdn.azureedge.net | AI Center does not load. |
| Complete OpenID configuration and receive service updates | https://cloud.uipath.comhttps://dc.services.visualstudio.comhttps://d2c7xlmseob604.cloudfront.nethttps://use.typekit.nethttps://fonts.googleapis.comhttps://aifstgassets.azureedge.nethttps://p.typekit.nethttps://fonts.gstatic.comhttps://api.smartling.comhttps://js-agent.newrelic.comhttps://i2.wp.com/cdn.auth0.comhttps://bam.eu01.nr-data.nethttps://du-prod-du-eus-signalr.service.signalr.netwss://du-prod-du-eus-signalr.service.signalr.net | AI Center authentication, configuration, or real-time updates may fail. |
| Access regional storage | Australia:https://aifproddataauetraining.blob.core.windows.netCanada: https://aifproddatacactraining.blob.core.windows.netEurope: https://aifproddatawetraining.blob.core.windows.netJapan: https://aifproddatajaetraining.blob.core.windows.netSingapore: https://aifproddataseatraining.blob.core.windows.netUnited States: https://aifproddataeustraining.blob.core.windows.netEuropean Union — delayed update (GxP): https://aifgxpdatawetraining.blob.core.windows.net | AI Center cannot upload, train, deploy, or manage machine learning resources. |
| Send service telemetry | https://bam.eu01.nr-data.nethttps://eastus-6.in.applicationinsights.azure.com | No user-facing functionality is affected, but service telemetry used for support is unavailable. |
AI Computer Vision
The following table lists the endpoint values and server locations used by AI Computer Vision:
| Endpoint value | Server location | Impact if blocked |
|---|---|---|
https://cv.uipath.com | Nearest geolocation based on the request IP | Studio and Robot cannot use AI Computer Vision activities. |
https://cv-eu.uipath.com | West Europe | Studio and Robot cannot use AI Computer Vision activities. |
https://cv-us.uipath.com | US | Studio and Robot cannot use AI Computer Vision activities. |
https://cv-delayed.uipath.com | Delayed enterprise ring deployment, located in the United States | Studio and Robot cannot use AI Computer Vision activities. |
AI Trust Layer – Bring your own LLM
IP ranges
Allow the following IP ranges to establish communication between the Bring your own LLM functionality of AI Trust Layer, and your own system. The Bring your own LLM functionality depends on Integration Service connectors for communication. To use this capability and create connections successfully, you must also add the unified IP ranges for Integration Service to your allowlist.
Table 1. IP ranges for Bring your own LLM
| Region | IP ranges |
|---|---|
| Australia | |
| Canada | |
| Europe (European Union) | |
| European Union delayed | |
| Community (Europe) | |
| India | |
| Japan | |
| Singapore | 20.43.184.90 |
| United Kingdom | |
| United States | |
| United States delayed | |
Apps
Domains
Allow the domains required for the Apps functionality that your organization uses:
| Scenario or functionality | Domains to allow | Impact if blocked |
|---|---|---|
| Open Apps | https://cloud.uipath.comhttps://fonts.googleapis.comhttps://cdnjs.cloudflare.comhttps://uipath-apps-prd.azureedge.nethttps://fonts.gstatic.comhttps://dc.services.visualstudio.comhttps://<orgname>.uipath.host | Apps does not load. |
| Create or import apps, or add or delete processes | https://cloud.uipath.comhttps://uipath-apps-prd.azureedge.net | The affected app-authoring operations do not work. |
| Export, clone, share, delete, edit, or publish an app | https://cloud.uipath.com | The affected app-management operations do not work. |
| Run or preview an app | https://cloud.uipath.comhttps://fonts.googleapis.comhttps://cdnjs.cloudflare.comhttps://uipath-apps-prd.azureedge.nethttps://fonts.gstatic.comhttps://dc.services.visualstudio.comhttps://<orgname>.uipath.hosthttps://api.uipath.com | The app cannot run or render correctly. |
| Select processes or create a rule | https://uipath-apps-prd.azureedge.net | Process selection and rule creation do not work. |
| Bind a process | https://uipath-apps-prd.azureedge.nethttps://cloud.uipath.comhttps://dc.services.visualstudio.com | Process binding does not work. |
| Create or delete pages or history entries | https://cloud.uipath.com | Apps does not load, so page and history operations are unavailable. |
| Connect to Apps | *.trafficmanager.netwss://*.uipath.systemswss://cloud.uipath.com | Apps does not load. Real-time collaboration updates require a page reload, and simultaneous editing can cause runtime errors. |
IP ranges
The Apps service uses the IP ranges listed below for all external communications. The following table shows the available IP ranges for each region.
| Region | IP ranges |
|---|---|
| Europe | |
| Europe (Secondary) | |
| Europe - Community | |
| Europe - Community (Secondary) | |
| US | |
| US (Secondary) | |
| Canada | |
| Canada (Secondary) | |
| Singapore | |
| Japan | |
| Japan (Secondary) | |
| Australia | |
| Australia (Secondary) | |
| India | |
| India (Secondary) | |
| UK | |
| UK (Secondary) | |
| United States — delayed update (GxP), secondary | |
| United States — delayed update (GxP) | |
Traffic from this IPs needs to be allowed through the Organization DMZ firewall and any other intermediate firewalls including the firewall on the computer/s in which Orchestrator application is hosted.
- The associated port on which Orchestrator application is hosted needs to be exposed through the DMZ on all relevant firewalls (see the previous point).
- An Orchestrator user who has read and execute access to relevant processes whose credential will be used from UiPath Apps to talk to Orchestrator.
- If using local robot process execution through RobotJS, please ensure RobotJS is properly configured using instructions provided at RobotJS.
Best practices
- Ensure that the On-Premise hosted Orchestrator is only accessible through a secure HTTPS channel.
- Create a low privilege user in Orchestrator that only has read and execute access to just the desired processes/folders and use that for the integration.
CORS policy requirements for Storage Buckets
When using storage buckets from an on-premises or hybrid Orchestrator, add https://cloud.uipath.com to the acceptedRootURLs list in the UiPath.Orchestrator.dll.config file.
- If your Orchestrator instance is hosted in Test Cloud, this configuration is already in place.
- For external buckets, configure the allowed origins as described in the CORS and CSP configuration guide."
UiPath Apps uploads and downloads files using the SAS URL generated by Orchestrator when interacting with storage buckets hosted in an on-premises environment. End users must have the appropriate permissions granted through that SAS URL to perform both upload and download operations.
All access control is defined and enforced by the underlying storage account configuration. UiPath does not manage or override these permissions.
If users encounter errors when uploading or downloading files through UiPath Apps, the storage account's SAS policies or access restrictions should be reviewed and updated by the storage owner to ensure the required level of access.
Content types to add to the allow list
UiPath Apps utilizes the content types application/octet-stream and application/zip for downloading specific DLL files required to run and preview created applications. It is important to ensure the following content types are allowed within your network settings to avoid interruptions in app functionality:
application/zip
application/octet-stream
application/json
text/html
application/javascript
text/css
font/woff2
image/vnd.microsoft.icon
image/svg+xml
image/bmp
image/jpeg
image/png
image/gif
application/zip
application/octet-stream
application/json
text/html
application/javascript
text/css
font/woff2
image/vnd.microsoft.icon
image/svg+xml
image/bmp
image/jpeg
image/png
image/gif
Key Considerations
Apps are developed using Blazor technology, which processes assemblies directly in the browser. If restrictions for the required content types cannot be lifted within your network, Apps may not function as expected, as there are no alternative solutions to bypass these limitations.
Apps in Studio Web as an alternative
Apps in Studio Web are designed with a different architecture, that does not require downloading DLL files. If network restrictions prevent the use of Standalone Apps, consider adopting Apps in Studio Web (RPA Apps). This architecture eliminates dependency on restricted content types, ensuring smoother compatibility in restricted network environments.
Automation Cloud Robots - Serverless
IP ranges
IP ranges for Automation Cloud Robots - Serverless enable you to route outbound network traffic through a dedicated, static IP address ranges managed by UiPath. This lets you allowlist or securely integrate with external systems that restrict incoming connections to known IPs.
Configuration
You can enable static IP ranges while creating the Serverless template and going to the Network Configuration page.
Availability
The IP ranges can sometimes change as a result of infrastructure deployments. To help keep you on top of any changes, we have compiled a list of up-to-date static IP ranges, in the following tables.
Community Users
| Region | CIDR | IP ranges |
|---|---|---|
| Europe | | |
Enterprise Users
| Region | CIDR | IP ranges |
|---|---|---|
| Australia | | |
| United States | | |
| Japan | | |
| Europe (European Union) | | |
Automation Hub
Domains
Allow the domains required for the Automation Hub functionality that your organization uses:
| Scenario or functionality | Domains to allow | Impact if blocked |
|---|---|---|
| Open Automation Hub | https://cloud.uipath.comhttp://*.userpilot.iohttps://dc.services.visualstudio.comhttps://ah-prod-ts-blue-eu.uipath.comhttps://ah-prod-ts-blue-us.uipath.comhttps://ah-prod-ts-blue-ja.uipath.comhttps://ah-prod-ts-blue-au.uipath.comhttps://ah-prod-ts-blue-ca.uipath.comhttps://ah-prod-ts-blue-sea.uipath.comhttps://ah-prod-ts-blue-uk.uipath.comhttps://ah-prod-ts-blue-in.uipath.comhttps://ah-gxp-ts-blue-us.uipath.com | Automation Hub may not load. If Userpilot is blocked, first-time guidance is unavailable. If the telemetry endpoint is blocked, support telemetry is unavailable. |
| Use the Automation Hub Open API | https://automation-hub.uipath.comhttp://ah-gxp-openapi-us.uipath.com | Optional. Automation Hub Open API calls fail. |
Automation Ops
Domains
Allow the domains required for the Automation Ops functionality that your organization uses:
| Scenario or functionality | Domains to allow | Impact if blocked |
|---|---|---|
| Open Automation Ops | https://stdadmstgcdn.azureedge.nethttps://stdadmstgcdn.blob.core.windows.nethttps://nexus.ensighten.comhttps://cloud.uipath.comhttps://platform-cdn.uipath.comhttps://use.typekit.nethttps://p.typekit.nethttps://content.usage.uipath.comhttps://data.usage.uipath.comhttps://*.service.signalr.netwss://*.service.signalr.nethttps://s.gravatar.comhttps://i2.wp.com | Automation Ops does not load or render correctly, and real-time updates are unavailable. |
| Use Source Control | https://github.comhttps://github.githubassets.comhttps://avatars.githubusercontent.comhttps://collector.github.comhttps://api.github.com | Source Control does not work. |
| Use Pipelines and send telemetry | https://app.vssps.visualstudio.comhttps://dc.services.visualstudio.com | Pipelines do not work. Blocking the telemetry endpoint also prevents support telemetry from being collected. |
IP ranges
The table below lists all IP ranges used by Automation Ops.
| Region | IP ranges |
|---|---|
| Australia | |
| Japan | |
| United States | |
| United States — delayed update (GxP) | |
| Europe | |
| European Union — delayed update (GxP) | |
| Canada | |
| Singapore | |
| India | |
| UK | |
IXP
Domains
Allow the domains required for IXP:
| Scenario or functionality | Domains to allow | Impact if blocked |
|---|---|---|
| Open IXP and authenticate | https://cloud.uipath.com | IXP is unavailable. |
| Load static assets | https://fonts.googleapis.comhttps://fonts.gstatic.com | Some interface elements may not render correctly. |
| Receive real-time portal updates | *.service.signalr.net | Notifications and other portal updates do not appear until the page is refreshed. |
| Send service telemetry | https://*.in.applicationinsights.azure.comhttps://dc.services.visualstudio.com | Core functionality remains available, but business telemetry and diagnostic logs are unavailable. |
| Use Pendo in-app guidance | https://*.pendo.io | IXP remains available, but onboarding and interactive help are unavailable. |
| Send performance-monitoring data | https://o486811.ingest.sentry.io | No user-facing functionality is affected, but performance diagnostics are unavailable. |
Inbound IP ranges
This section applies only to legacy Re:infer customers.
Add the following inbound IP ranges to your allow list to use IXP and create connections:
| Region | Inbound IP ranges |
|---|---|
| Europe | 34.91.100.206 |
| US | |
| Japan | 34.84.144.176 |
| Australia | 35.189.46.91 |
| Canada | 34.152.10.176 |
| Singapore | 35.240.179.214 |
IP ranges
Allow the following IP ranges for IXP to sync emails from your Exchange. For details, check the Overview Exchange integration.
| Region | IP ranges |
|---|---|
| Europe | 35.204.220.118 |
| US | 34.71.173.219 |
| Japan | 34.84.107.92 |
| Australia | 34.87.223.173 |
| Canada | 34.152.42.160 |
| Singapore | 34.143.128.81 |
Data Fabric
Domains
Allow the domains required for Data Fabric:
| Scenario or functionality | Domains to allow | Impact if blocked |
|---|---|---|
| Use Data Fabric | https://cloud.uipath.com | Data Fabric is unavailable. |
| Send service telemetry | *.visualstudio.com | No user-facing functionality is affected, but service telemetry is unavailable. |
Document Understanding
Domains
Allow the domains required for the Document Understanding functionality that your organization uses:
| Scenario or functionality | Domains to allow | Impact if blocked |
|---|---|---|
| Open Document Understanding | https://*.uipath.com | Document Understanding does not load. |
| Send optional Azure telemetry | https://*.azure.com | Optional. Core functionality remains available, but telemetry used to investigate issues is unavailable. |
| Load the frontend | https://*.azureedge.net | Document Understanding does not load. |
| Receive real-time updates | https://*.service.signalr.netwss://*.service.signalr.net | Real-time updates do not appear until the page is refreshed. |
| Access legacy Document Manager storage | https://*.blob.core.windows.net | Document Manager does not work for projects created before 2023. |
| Use Pendo in-app guidance | https://*.pendo.io | Optional. In-product announcements and interactive guidance are unavailable. |
| Access public endpoints | See Public endpoints for the full list. | Information about predefined models and other public-endpoint functionality is unavailable. |
The legacy Document Manager storage domains apply only to projects created before 2023.
Cloudflare IP range fallback
If your network equipment does not support DNS-based allowlisting, you can use the Cloudflare IP range 104.16.0.0/13 as a fallback. DNS-based allowlisting is recommended because Cloudflare IP ranges are broad and may change.
Insights
Domains
The following table lists the domains used by Insights:
| Scenario | Domains to allow | Impact if blocked |
|---|---|---|
| Navigate to the Insights page | https://cloud.uipath.comhttps://*.lookercdn.comhttps://uipath-insights-statics.azureedge.net/https://*.looker.uipath.com/ | Insights may not load, and some dashboards or visualizations may be blank. |
IP ranges
IP ranges allow you to add a list of IPs for Log Export and Data Export features to the allowlist and not open your network to all external IPs. If the Blob storage regions correspond to the respective Insights service region, you cannot use public IPs.
| Insights service region | Blob storage region | Functionality | Static IP ranges |
|---|---|---|---|
| Europe |
| Log Export | |
| Data Export | | ||
| Looker SFTP notifications | | ||
| United States of America |
| Log Export | |
| Data Export | | ||
| Looker SFTP notifications | | ||
| Australia |
| Log Export | |
| Data Export | | ||
| Looker SFTP notifications | | ||
| Japan |
| Log Export | |
| Data Export | | ||
| Looker SFTP notifications | | ||
| Canada |
| Log Export | |
| Data Export | | ||
| Looker SFTP notifications | | ||
| Singapore |
| Log Export | |
| Data Export | | ||
| Looker SFTP notifications | | ||
| India |
| Log Export | |
| Data Export | | ||
| Looker SFTP notifications | | ||
| United Kingdom |
| Log Export | |
| Data Export | | ||
| Looker SFTP notifications | | ||
| United States — delayed update (GxP) |
| Log Export | 134.33.240.104 |
| Data Export | | ||
| Looker SFTP notifications | | ||
| European Union — delayed update (GxP) |
| Log Export | |
| Data Export | | ||
| Looker SFTP notifications | |
Limitations
For Log Export, Google Storage does not support inbound IP restriction.
Due to a limitation on Microsoft side for Log Export, you cannot set up inbound IP restriction when your Azure blob storage account and the Insights infrastructure is under the same region in Azure. Because of this, you cannot use the following regions for blob storage account based on the Insights service region:
- Insights US: North Europe, East US
- Insights Europe: North Europe, West Europe (For Community Licensing)
- Insights UK: North Europe, UK South
- Insights Canada: North Europe, Canada Central
- Insights Singapore: North Europe, Southeast Asia
- Insights India: North Europe, Central India
- Insights Australia: North Europe, Australia East
- Insights Japan: North Europe, Japan East
- Insights — European Union — delayed update (GxP): North Europe, East US
- Insights — United States — delayed update (GxP): East US
For more information on this limitation, check the Restrictions for IP network rules page from the Microsoft Azure Blob Storage documentation.
Integration Service
IP ranges
Add the following IP ranges to your allow list to use Integration Service and create connections, as described in the following table.
| Region | IP ranges | Environment |
|---|---|---|
| Australia | | Production |
| Canada | | Production |
| Europe | | Production |
| Japan | | Production |
| India | | Production |
| Singapore | | Production |
| United Kingdom | | Production |
| United States | | Production |
| United States — delayed update (GxP) | | Production |
| Community | | Production |
IP addresses marked with an asterisk () are designated for newly incorporated Azure regions. These IPs will supersede the existing regional IPs upon completion of the scheduled tenant migration process. For details, refer to the Integration Service release notes.
Orchestrator
Domains
Allow the domains required for Orchestrator and Robot functionality:
| Scenario or functionality | Domains to allow | Impact if blocked |
|---|---|---|
| Open Orchestrator | https://cloud.uipath.comhttps://orch-cdn.uipath.comhttps://account.uipath.com | The Orchestrator frontend does not load. |
| Connect Cloud Robots - VM to UiPath services | https://cloud.uipath.com | The Robot and agent on the provisioned VM cannot communicate with UiPath services. |
| Download Studio and Robot installers for Cloud Robots - VM | https://download.uipath.com | Optional if you install and manage the Robot yourself. Otherwise, Studio and Robot installers cannot be downloaded. |
| Access Orchestrator storage | *.blob.core.windows.netIf using Amazon S3 buckets: *.s3.amazonaws.com | Package upload and download, suspended jobs, video recording, storage buckets, and other storage-backed functionality do not work. Provisioned Cloud Robots - VM also cannot connect to UiPath infrastructure. |
| Download packages and libraries | https://pkgs.dev.azure.com | Libraries and packages from the host feed cannot be downloaded. |
| Use Azure SignalR | https://*.service.signalr.netwss://*.service.signalr.net | Real-time updates and live streaming fail, attended jobs cannot be stopped remotely, and some Robot or activity events can be delayed by up to 30 seconds. |
| Update Studio and Robot automatically | https://download.uipath.com | Studio and Robot cannot update automatically. |
| Use Live Streaming and Remote Control | *.uipath.comhttps://*.uipath.comwss://*.uipath.com | Live Streaming and Remote Control do not work. |
IP ranges
We recommend allowing these IP ranges, which send traffic from Orchestrator towards your resources. For details, refer to Orchestrator IP ranges.
Community users
| Region | CIDR | IP ranges |
|---|---|---|
| Europe (European Union) | | |
Enterprise users
| Region | CIDR | IP ranges |
|---|---|---|
| Australia | | |
| Canada | | |
| United States | | |
| Japan | | |
| Europe (European Union) | | |
| Singapore | | |
| United Kingdom | | |
| India | | |
Delayed update (GxP) organizations
| Region | CIDR | IP ranges |
|---|---|---|
| Europe (European Union) | | |
| United States | | |
MCP Servers
The remote MCP Servers service uses the IP ranges listed below for all external communications. The following table shows the available IP ranges for each region.
| Region | IP ranges |
|---|---|
| Europe | |
| Europe (Secondary) | |
| Europe - Community | |
| Europe - Community (Secondary) | |
| US | |
| US (Secondary) | |
| Canada | |
| Canada (Secondary) | |
| Singapore | |
| Japan | |
| Japan (Secondary) | |
| Australia | |
| Australia (Secondary) | |
| India | |
| India (Secondary) | |
| UK | |
| UK (Secondary) | |
| European Union — delayed update (GxP) | |
| European Union — delayed update (GxP), secondary | |
| United States — delayed update (GxP) | |
| United States — delayed update (GxP), secondary | |
Process Mining
Domains
Allow the domains required for Process Mining:
| Scenario or functionality | Domains to allow | Impact if blocked |
|---|---|---|
| Open Process Mining | https://cloud.uipath.com | Process Mining is unavailable. |
| Load static assets | https://fonts.googleapis.comhttps://fonts.gstatic.comhttps://content.usage.uipath.comhttps://s.gravatar.comhttps://i1.wp.com | Process Mining may not load or render correctly. |
| Receive real-time updates | https://*.service.signalr.netwss://*.service.signalr.net | The interface can display outdated information until the page is refreshed. |
| Send service telemetry | https://*.in.applicationinsights.azure.com | Optional. Core functionality remains available, but diagnostic information used for support is unavailable. |
| Upload data to Process Mining | *.blob.core.windows.net | Process Mining cannot ingest data or create process apps. |
Solutions
Domains
Allow the domains required for Solutions Management:
| Scenario or functionality | Domains to allow | Impact if blocked |
|---|---|---|
| Open Solutions Management | https://cloud.uipath.comhttps://fonts.googleapis.comhttps://fonts.gstatic.comhttps://dc.services.visualstudio.comapi.smartling.comuse.typekit.netp.typekit.nets.gravatar.comi2.wp.comhttps://platform-cdn.uipath.comhttps://sol-cdn.uipath.comhttps://solutions.uipath.com | Solutions Management or required interface assets may be unavailable. |
| Upload or download solution packages | *.blob.core.windows.net | Solution packages cannot be uploaded or downloaded. |
| Receive live deployment updates | https://*.service.signalr.netwss://*.service.signalr.net | Live status updates, including deployment progress, do not appear until the page is refreshed. |
Studio Web
Domains
Allow the domains required for Studio Web:
| Scenario or functionality | Domains to allow | Impact if blocked |
|---|---|---|
| Receive real-time collaboration updates | wss://*.service.signalr.nethttps://*.service.signalr.netwss://*.trafficmanager.net | Live updates for project imports, shared projects, and other notifications are unavailable. |
| Open Studio Web | https://*.uipath.com | Studio Web is unavailable. |
| Send in-app feedback | https://studio-feedback.azure-api.net | In-app feedback cannot be submitted. |
| Load static assets | https://platform-cdn.uipath.comhttps://content.usage.uipath.comhttps://fonts.gstatic.comhttps://d2c7xlmseob604.cloudfront.nethttps://fonts.googleapis.comhttps://*.typekit.nethttps://s.gravatar.comhttps://secure.gravatar.comhttps://*.wp.comhttps://*.googleusercontent.comhttps://i.ytimg.com | Fonts, icons, images, or other static assets may not render correctly. |
| Send product telemetry | https://data.usage.uipath.com | Optional. Core functionality remains available, but product telemetry is unavailable. |
| Use Pendo in-app guidance | https://*.pendo.io | Optional. In-app guidance is unavailable. |
| Send third-party telemetry | https://dc.services.visualstudio.com | Core functionality remains available, but diagnostic telemetry is unavailable. |
| Load translated interface content | https://api.smartling.com | Translated interface content may be unavailable. |
Task Mining
Domains
Allow the domains required for Task Mining desktop components:
| Scenario or functionality | Domains to allow | Impact if blocked |
|---|---|---|
| Open Task Mining | https://cloud.uipath.com | Task Mining is unavailable. |
| Use the web portal | *.blob.core.windows.net | The Task Mining web portal does not function correctly. |
| Receive desktop-component notifications | *.service.signalr.net | The desktop component may not receive real-time updates. |
| Use Pendo in-app guidance | https://content.usage.uipath.com | In-app guidance is unavailable. |
| Send Azure Application Insights telemetry | dc.services.visualstudio.comdc.applicationinsights.azure.comdc.applicationinsights.microsoft.com*.in.applicationinsights.azure.comlive.applicationinsights.azure.comrt.applicationinsights.microsoft.comrt.services.visualstudio.com{region}.livediagnostics.monitor.azure.com | Core functionality remains available, but diagnostic telemetry is unavailable. |
| Load user avatars | i2.wp.com/cdn.auth0.com/avatars | User avatars do not render. |
Task Mining uses HTTPS and WSS over port 443. Configure transparent proxies to permit both protocols.
Test Manager
This section lists the domains used by Test Manager and the IP ranges that you should consider allowing if you want to use various Test Manager capabilities.
Domains
Allow the domains required for Test Manager:
| Scenario or functionality | Domains to allow | Impact if blocked |
|---|---|---|
| Open Test Manager | https://cloud.uipath.com | Test Manager is unavailable or its interface does not render correctly. |
| Receive real-time updates | https://*.service.signalr.netwss://*.service.signalr.net | Some interface updates do not appear until the page is refreshed. |
SAP Heatmap and CIA RFC IP ranges
Allow the following IP ranges to establish communication between UiPath Test Manager and your SAP system via an RFC connection.
The following table shows the available IP ranges for each region.
| Region | IP ranges |
|---|---|
| Australia | |
| Canada | |
| Europe (European Union) | |
| India | |
| United States — delayed update (GxP) | |
| Japan | |
| Singapore | |
| United Kingdom | |
| United States | |
SAP Heatmap and CIA Web Service IP ranges
Allow the following static IP ranges to enable the communication between UiPath Test Manager and your SAP system, via a web service connection.
Allow these IP ranges through your firewall:
| Regions | IP ranges |
|---|---|
| Australia | |
| Canada | |
| Community | |
| European Union | |
| European Union — delayed update (GxP) | |
| India | |
| Japan | |
| Singapore | |
| United Kingdom | |
| United States | |
| United States — delayed update (GxP) | |
IP ranges for connectors
If you enhance your system's security with a firewall, consider allowing only Test Manager IP ranges for using out-of-the-box connectors.
The following IP ranges apply to all supported regions, including: Australia, Canada, European Union, India, Japan, Singapore, United Kingdom, United States, and United States — delayed update (GxP).
Allow these IP ranges through your firewall:
| Regions | IP ranges |
|---|---|
| Australia, Canada, European Union, India, Japan, Singapore, United Kingdom, United States, and United States — delayed update (GxP) | |
- Deprecation notice
- What is changing
- Timeline
- What you need to do
- Test Cloud Portal
- Domains
- IP ranges to enable a firewall for the customer-managed key
- IP ranges for notifications
- Relay
- Action Center
- Domains
- AI Center
- Domains
- AI Computer Vision
- AI Trust Layer – Bring your own LLM
- IP ranges
- Apps
- Domains
- IP ranges
- Content types to add to the allow list
- Automation Cloud Robots - Serverless
- IP ranges
- Automation Hub
- Domains
- Automation Ops
- Domains
- IP ranges
- IXP
- Domains
- Inbound IP ranges
- IP ranges
- Data Fabric
- Domains
- Document Understanding
- Domains
- Cloudflare IP range fallback
- Insights
- Domains
- IP ranges
- Integration Service
- IP ranges
- Orchestrator
- Domains
- IP ranges
- MCP Servers
- Process Mining
- Domains
- Solutions
- Domains
- Studio Web
- Domains
- Task Mining
- Domains
- Test Manager
- Domains
- SAP Heatmap and CIA RFC IP ranges
- SAP Heatmap and CIA Web Service IP ranges
- IP ranges for connectors