IP addresses

The fixed IP address Railcode connects from, so you can allow it through a firewall.

Railcode connects to your systems from one fixed IP address:

34.211.16.38

If your database or API only accepts traffic from known addresses, add this one to its allow list. As a CIDR range, it is 34.211.16.38/32.

The address does not change when we deploy or restart. We only connect out from it, so you never need to send traffic to it.

What connects from this address

Every call that Railcode makes to your systems on your behalf:

  • Data connections. Every query to your database, including saved queries and direct SQL. Railcode connects to the database when an admin creates the connection, so a firewall that still blocks us fails at that step.
  • Connectors. Every call an http connector proxies to your API, and every tool call to an mcp connector's server.
  • Managed agents. An agent reaches your data connections and connectors through Railcode, so its calls come from this address too.
  • Apps. When a backend function reads a data connection or calls a connector, Railcode makes the call from this address.
  • AI models. Calls to the model providers your org configures.

What does not

Hosts that a backend function calls directly. A backend function can call a host declared under egress: itself. Those requests come from a shared pool of addresses that changes over time, so an IP allow list cannot admit them. If the host only accepts known addresses, set it up as a connector instead. Railcode then makes the call from the address above.

Ports

Open only the port your service listens on. That is usually 5432 for Postgres and 443 for an HTTPS API.

On this page