Which domains do we add to our network's 'Allowed List' to ensure access to Procore?

Background

To ensure Procore works correctly on your network, your IT department may need to add the domains and addresses below to your network's allowed list. This includes the IP addresses Procore uses to send webhook, integration, or agent traffic — see the Procore Outbound Traffic Allowed List section below.

 Important note on maintenance

Last updated September 15, 2026. Procore updates this list as our services evolve. To prevent access problems, ask your IT department to bookmark this page and check it regularly to keep your organization's allowed list up-to-date. We also recommend subscribing to status.procore.com to receive maintenance alerts.

Answer

Procore Platform Allowed Domains

Procore recommends adding a wildcard entry, which is the most comprehensive and future-proof configuration:

  • *.procore.com

If your network security policies do not permit wildcard entries or you require a more granular list, add the specific domains below. Note: Domains marked with an asterisk (*) do not require you to add each sub-domain.

Procore Services:

  • *.procore.com

  • *.cdn.procore.com

  • *.pages.procore.com

  • api.procore.com

  • app.procore.com

  • assets0.procore.com

  • assets1.procore.com

  • assets2.procore.com

  • assets3.procore.com

  • events.procore.com

  • learn.procore.com

  • login.procore.com

  • my.procore.com

  • storage.procore.com

  • support.procore.com

  • us02.procore.com

Required Third-Party and Supporting Services:

  • *.bugsnag.com

  • *.launchdarkly.com

  • *.pendo.io

  • *.salesforceliveagent.com

  • *.uservoice.com

  • a.mtstatic.com

  • bam.nr-data.net

  • by2.uservoice.com

  • c.la4-c2-was.salesforceliveagent.com

  • chat.stream-io-api.com

  • cloudflare.com

  • consent.truste.com

  • d.la4-c2-was.salesforceliveagent.com

  • d3sbxpiag177w8.cloudfront.net

  • files.mtstatic.com

  • fonts.googleapis.com

  • fonts.gstatic.com

  • js-agent.newrelic.com

  • maxcdn.bootstrapcdn.com

  • pages.dev

  • rs.fullstory.com

  • s3.amazonaws.com

  • sdk.iad-01.braze.com/api/v3/data

  • sdk.iad-05.braze.com/api/v3/data

  • us01-i-prod-estimating-storage.s3.amazonaws.com

  • widget.uservoice.com

  • www.glancecdn.net

  • www.google.com

Network Ports and Protocols

Please ensure your network allows outbound traffic for the following protocols:

Protocol

Port

HTTPS (TLS)

443 (TCP)

WebSocket Secure (WSS)

443 (TCP)

Procore Email Delivery Allowed List

Add these email domains and IP addresses dedicated to Procore email notifications, reports, and messages.

  • procore.com

  • procoretech.com

  • click.procore.com

  • customer.procore.com

  • fastly.net

  • message.procore.com

  • update.procore.com

  • us02.procoretech.com

  • uk01.procoretech.com

  • sbx.procoretech.com

  • smtp.sendgrid.net

  • skilljar.com

  • surveys.procore.com

Outbound Email IP Addresses

These are stable IP addresses used for email delivery only. They are not related to the outbound traffic addresses listed later in this article.

  • 137.22.225.98

  • 137.22.227.19

  • 137.22.228.37

  • 137.22.228.47

  • 167.89.22.86

  • 167.89.23.21

  • 167.89.24.90

  • 167.89.36.250

Procore Outbound Traffic Allowed List

In some configurations, Procore sends data out to systems you host or control. If you allow Procore by domain name, no action is required, but if your firewall or proxy restricts inbound connections to specific source IP addresses, add the below to accept Webhook, Integration, and Agent Server Traffic.

Webhooks and Integrations

Add both sets of IP addresses below if you use Procore Webhooks to deliver events to an endpoint you run or if an integration connects Procore to an ERP or other system on your own infrastructure,

Allow all of the addresses below, not only your own region. Procore may route this traffic through a region other than the one hosting your account, for example during failover or maintenance. Allowing only one region can cause events to be dropped without warning.

North America

  • 3.92.249.167

  • 52.20.249.109

  • 18.210.56.138

  • 98.80.37.45

  • 44.193.174.219

  • 3.130.85.183 - New

  • 18.220.58.45 - New

  • 18.216.158.63 - New

  • 100.20.90.249

  • 35.85.233.134

  • 54.69.79.116

  • 34.211.2.207

  • 3.215.34.250 - Sunsetting

  • 54.243.188.212 - Sunsetting

  • 18.235.207.254 - Sunsetting

  • 44.235.249.18 - Sunsetting

  • 44.227.10.201 - Sunsetting

  • 54.212.4.87 - Sunsetting

Europe

  • 52.58.26.101 - New

  • 18.157.145.209 - New

  • 3.78.1.115 - New

  • 18.175.100.125

  • 3.10.230.217

  • 35.176.69.103

Agent Server (Procore AI & Datagrid)

Some agents, including agents used in Procore AI and Datagrid, connect to external systems outside of Procore, such as a customer's own application or API, to complete an action. If the organization restricts inbound traffic with a firewall, that traffic may be blocked unless the source is recognized. This applies to Datagrid standalone customers with API integrations, as well as Procore AI customers whose agents are configured to call an external, firewall-protected system. If you are not sure whether your agents call an external system outside of Procore, check with the team that configured the agent — for example your Forward Deployed Engineering contact.

Agent Server traffic uses its own addresses, not the regional addresses above. Add both of these addresses:

  • 54.174.198.5

  • 34.196.65.237

These addresses are designed to stay consistent across infrastructure updates, which can help reduce ongoing firewall maintenance for organizations with restricted network policies.

Important
  • Applicability: These outbound addresses apply to Procore production and sandbox environments, including Monthly Sandbox and Developer Sandbox. They do not apply to Procore for Government, which runs on separate infrastructure. If your organization uses Procore for Government, contact your Procore account team for the network requirements that apply to it.

  • If you do not add these addresses to your allow list: Procore will be unable to reach your systems. Webhook events will not arrive, syncs to systems you host will stop, and agent actions that call your external systems will fail. These failures are not visible to Procore and will not generate an error on our side, so your IT team will need to add the addresses above before service resumes.


See Also

Loading related articles...