IP addresses
The fixed IP address Railcode connects from, so you can allow it through a firewall.
Railcode connects to your systems from one fixed IP address:
34.211.16.38If your database or API only accepts traffic from known addresses, add this one to its allow
list. As a CIDR range, it is 34.211.16.38/32.
The address does not change when we deploy or restart. We only connect out from it, so you never need to send traffic to it.
What connects from this address
Every call that Railcode makes to your systems on your behalf:
- Data connections. Every query to your database, including saved queries and direct SQL. Railcode connects to the database when an admin creates the connection, so a firewall that still blocks us fails at that step.
- Connectors. Every call an http connector proxies to your API, and every tool call to an mcp connector's server.
- Managed agents. An agent reaches your data connections and connectors through Railcode, so its calls come from this address too.
- Apps. When a backend function reads a data connection or calls a connector, Railcode makes the call from this address.
- AI models. Calls to the model providers your org configures.
What does not
Hosts that a backend function calls directly. A backend function can call a host declared
under egress: itself. Those requests come from a shared pool of addresses that changes over
time, so an IP allow list cannot admit them. If the host only accepts known addresses, set it
up as a connector instead. Railcode then makes the call from the
address above.
Ports
Open only the port your service listens on. That is usually 5432 for Postgres and 443 for
an HTTPS API.