Skip to content

Network access

If your firewall, Snowflake network policy, Salesforce IP restrictions, or other inbound controls require allowlisting, Sonora’s outbound traffic comes from these static addresses:

34.58.87.210
136.116.134.112
104.154.162.85
34.135.230.108

These addresses don’t change without advance notice. If we ever need to add or rotate one, you’ll hear from us before the change takes effect, with enough lead time to update your allowlists.

Most integrations don’t require allowlisting because they reach into Sonora rather than the other way around (Salesforce/HubSpot OAuth flows, for instance, are triggered from Sonora and complete in the browser). The cases that do require allowlisting are the ones where Sonora pulls data from your environment:

  • Snowflake connections, when the Snowflake account uses a network policy
  • BigQuery connections, when project-level IAM is locked down to specific networks
  • Salesforce connections, if the integration user’s profile enforces login IP ranges

Add the four addresses above to whichever allowlist applies.