Skip to main content
When communicating with on-premise services e.g. Jira Server, or other services which may enforce IP-allowlisting (e.g. Gitlab or GitHub), we use specific IP addresses. Some services, when run in an on-premise or enterprise SaaS configuration, encourage you to use IP addresses to filter traffic from unknown sources, however we strongly recommend that you use additional strategies to secure your instance, including SSL/TLS.

IP addresses

To keep a firewall rule up to date automatically, fetch these from GET /v1/ip_ranges instead of copying them from this page. The endpoint needs no API key, and each entry says which of our traffic uses it. The following IP addresses are currently used:
If using our Investigations product, access must be allowed from additional IP addresses:

Further information

All IP addresses stated above are reserved solely for incident.io application usage only, and not shared with other organizations or infrastructure. We will send notice 2 weeks in advance of any changes to this list, to all customers using an integration dependent on these addresses. These are the addresses we send requests from. They are not the addresses our API is served on, which change without notice and should not be allowlisted for inbound access. All requests from incident.io to on-premise integrations are made using secure cryptography to protect data in transit.
To ensure changes to follow-ups in Jira Server specifically sync back to incident.io, you’ll need to register a webhook. Learn how to register a Jira Server webhook.