Skip to main content
When Fini executes an Action against your systems, looking up an order, checking a subscription, resetting a password, it makes an outbound HTTPS call to your API. If your firewall restricts inbound traffic by source IP, you’ll need to allow the addresses those calls come from. Fini routes all outbound traffic through a fixed set of static IPs, so you can whitelist them once and never revisit it.
These addresses cover outbound calls only, the requests Fini sends to your systems when running Actions. They don’t affect how you send requests to the Fini API, and they don’t change how your widget or helpdesk integration connects. If you only call Fini and Fini never calls you back, you don’t need to whitelist anything.

IPs to whitelist

Allow all of the following addresses in your firewall:
Traffic can originate from any of the four. They exist for redundancy and load distribution, so a given request may arrive from any one of them. The addresses are hosted in Google Cloud’s europe-west4 region (Eemshaven, Netherlands). They’re static and won’t change without advance notice.
Whitelist all four addresses, not a subset. Allowing only one or two causes intermittent failures that are hard to diagnose, calls succeed when they happen to route through an allowed IP and time out when they don’t.

Setting it up

1

Add the four IPs to your allowlist

Allow inbound HTTPS (port 443) from each of the four addresses on the endpoints your Actions call.
2

Confirm with your Fini contact

Let us know once the rules are live. We’ll run a test Action against your endpoint to confirm the call lands.
3

Verify the call succeeds

A successful test means the route is open. If it times out, the allowlist usually hasn’t propagated yet or one of the four IPs is missing, see below.
If you’re integrating against a sandbox, staging API, or staging warehouse first, ask your Fini contact for the staging IPs. They’re a separate, smaller set and aren’t listed here. For the full warehouse setup pattern, see Database and Warehouse Connections.

Why calls aren’t getting through

You’ve likely whitelisted a subset of the four addresses. Traffic distributes across all of them, so partial allowlisting produces intermittent timeouts. Add all four.
Either the rules haven’t propagated on your side, or the firewall is filtering on the wrong port or endpoint. Confirm the rules apply to the exact host and path your Actions hit, on port 443.
The addresses don’t rotate silently, we notify before any change. A sudden break is almost always a firewall rule that was edited or expired on your side, or an endpoint that moved. Re-check the allowlist, then reach out to your Fini contact.

Actions

The outbound calls Fini makes to your systems. These are the requests that originate from the static IPs.

Database and Warehouse Connections

How to put a scoped HTTPS endpoint in front of Redshift, Snowflake, BigQuery, Postgres, or another warehouse.

API keys

Public API access for your own backend integrations with Fini.