Static IP for whitelisting
Render from a fixed Urlbox IP address that you can allowlist on your firewall, WAF or staging site
New: the static_ip option is new. Tell us at support@urlbox.com if you need another region.
static_ip is available on the Business plan and above (including Enterprise). On other plans a request with static_ip is rejected with a 400 OptionNotAvailableOnPlan error. See pricing to upgrade, or contact support@urlbox.com.
Urlbox normally renders from a pool of cloud IP addresses that change over time, so you can't allowlist them. If the site you render only accepts known IPs (a staging site behind a firewall, an intranet page, a WAF rule or an API with an IP allowlist), set static_ip and the render comes from one of the fixed addresses below.
Our static IP addresses
Allowlist the addresses for the regions you use:
| Region | static_ip value | IP address |
|---|---|---|
| US East (South Carolina) | us-east | 34.24.190.176 |
| US West (Oregon) | us-west | 34.187.238.195 |
| Europe (Netherlands) | eu | 34.158.137.109 |
These addresses are reserved for this purpose and do not change. If we ever add or replace one, we'll tell you in advance.
Rendering from a static IP
Pass a region to always render from that region's IP:
{ "url": "https://staging.example.com", "static_ip": "eu"}Or set static_ip to true to use any of our static IPs. In that case, allowlist all the addresses above, because the render can come from any region:
{ "url": "https://staging.example.com", "static_ip": true}Every request the page makes goes out through the static IP: the page itself, and also its scripts, styles, images, fonts and API calls, including those to other domains. So the site never sees a request from any other Urlbox IP.
You can set static_ip as a default option on a project so that every render in that project uses it. The plan requirement applies to project defaults too.
Combining with other options
static_ip works with every other render option except the ones that pick a different route to the site:
A request that combines static_ip with one of these is rejected with a 400 error that names the conflicting option. This includes a retry_with step that sets one of them, because every attempt of a static IP render has to come from the static IP.
When Urlbox retries a blocked static IP render for you, the retry can use stealth, wait out a challenge, and so on, but it still comes from the static IP. It never switches to a different IP or proxy.
Things to know
- The static IPs are shared by all Urlbox customers who use
static_ip. Allowlisting them lets in traffic from Urlbox, not from you alone. To make sure a request came from you, combine the allowlist with a secret: for example aheaderorcookiethat your site checks. - Because the static IPs are known datacenter addresses, they don't help you get past bot protection. To avoid blocks, see avoiding being blocked.
- If a region's static IP is unavailable, the request fails with a
400error rather than rendering from another IP.