Skip to main content
Configure agent environment

IP Addresses

Cloud Agents uses the same fixed egress IP address pool for MCP tool calls and webhook deliveries. You can use these addresses to configure firewall allowlists so your MCP servers and webhook endpoints accept requests from Cloud Agents. These addresses are used for outbound MCP tool calls and webhook deliveries and are not shared with sandbox public-network egress. They will not change without advance notice.

Outbound IP Addresses (MCP and Webhooks)

Cloud Agents uses the following fixed egress IP range when calling MCP tools on external servers or delivering webhooks to your endpoints:
8.216.144.48/28

Firewall Configuration

If your MCP server or webhook endpoint restricts incoming traffic by source IP, add the CIDR block above to your inbound firewall allowlist to accept MCP tool calls and webhook deliveries from Cloud Agents.
This IP range applies to egress for MCP tool calls and webhook deliveries. It does not apply to sandbox-container public egress.

FAQ

Q: Will these IP addresses change? A: Not without advance notice. If the range is changed or rotated, we will announce the update with sufficient lead time for you to update firewall rules. Q: Do sandbox outbound connections also come from these IPs? A: No. Sandbox public-network egress uses a different IP pool. The range on this page is used for MCP tool calls and webhook deliveries made by the platform.