Skip to main content
When a Datagrid agent calls your HTTPS endpoint (including an MCP server), the request originates from a small, stable set of public IPv4 addresses. Allowlist these addresses on your firewall if you restrict inbound traffic by source IP. These are egress (outbound) source IPs — the addresses you see when Datagrid calls you. They are not inbound addresses for reaching api.datagrid.com. Production is in AWS us-east-1.

Allowlist

Allow both production addresses. Traffic may leave through either IP.

What these IPs cover

Traffic from the Datagrid Agent Server (the process that runs converse and agent tool calls), including:
  • Outbound calls to registered and inline MCP servers
  • Other HTTPS calls the Agent Server makes to partner APIs as part of an agent run

What these IPs do not cover

Do not expect the addresses above for:
  • Inbound access to the Datagrid API or app
  • Connector, ingest, JDBC, Airbyte, or webhook-delivery traffic (those workloads use a different, separately pinned IP set)
  • Datagrid-hosted MCP Lambdas calling third parties (those functions are not on this NAT)
  • Indexing, automation, or other background tasks that are not the Agent Server
  • Datagrid deployments inside a Procore / FedRAMP boundary (those use platform-managed NAT addresses, not this list)
If your integration also receives connector ingest or Datagrid webhook delivery, ask your Datagrid contact for that separate allowlist rather than reusing this page.

Changes and new regions

Published IPs will not rotate silently. If an address must change, we will update this page and give advance notice before the old address stops being used. When Datagrid adds a region, that region gets its own source IPs. We will add them here before that region sends partner-bound traffic. Prefer allowlisting both production addresses rather than a single IP.