Skip to main content
Cloud Agents uses a fixed IP address pool for outbound connections made by MCP tool calls. You can use these addresses to configure firewall allowlists so your MCP servers accept traffic from Cloud Agents. These addresses are dedicated to MCP outbound traffic and are not shared with sandbox public-network egress. They will not change without advance notice.

Outbound IP Addresses (MCP)

The stable IP range that Cloud Agents uses when an Agent invokes an MCP tool that connects to your external server:

Firewall Configuration

To allow MCP tool calls from Cloud Agents to reach your server, add the CIDR block above to your inbound firewall rules.
This IP range applies only to MCP tool-call egress. Sandbox containers with unrestricted or allowed_hosts networking use separate, non-overlapping public IP ranges and are not covered here.

FAQ

Q: Will these IP addresses change? A: Not without advance notice. If the range is changed or rotated, we will announce the update with sufficient lead time for you to update firewall rules. Q: Do sandbox outbound connections also come from these IPs? A: No. Sandbox public-network egress uses a different IP pool. The range on this page is exclusively for MCP tool calls made by the platform on behalf of an Agent.