Overview
Tulip is designed to be a versatile tool, but a high-quality network connection is required to reach it reliably. This article lists the specific domains, IP address ranges, and ports to allowlist for Tulip Cloud — covering the Tulip platform, Admin interface, Connector Hosts, Edge Devices, and Tulip Player.
For network stability requirements, data-integrity risk, and resilient app design guidance, see Network Stability and Data Integrity Requirements for Tulip Cloud Deployments.
Also see: Network Troubleshooting Guide
Who is this article for?
This article is most useful for IT and network teams configuring firewall, proxy, and connectivity settings for a Tulip Cloud deployment.
Use the links on the right to navigate to relevant sections.
Allowlist
The section below lists all connections Tulip requires to operate as a platform, separated by Tulip component. This list represents a complete list of addresses owned by Tulip.
Users can identify the garden identifier where their Tulip Instance is hosted within the Account Settings menu.
| Garden Identifier | Inbound to Tulip Cloud Services (Outbound from Customer Network to Tulip Cloud Services) | Outbound from Tulip (Inbound from Tulip Cloud Services to Customer Network) | Asset Storage |
|---|---|---|---|
eu-32* |
|
|
|
eu-70* |
|
|
|
apac-94* |
|
|
|
us-11* |
|
|
|
us-14* |
|
|
|
us-15* |
|
|
|
apac-19* |
|
|
|
cn-20* |
|
|
|
cn-21* |
|
|
|
usgov-22* |
|
|
|
apac-25* |
|
|
|
eu-27* |
|
|
|
us-28* |
|
|
|
apac-30* |
|
|
|
us-33* |
|
|
|
us-34* |
|
|
|
apac-35* |
|
|
|
Admin interface (Web Browser)
To use Tulip's web interface, we require the following:
Requirements
Outgoing access to Factory:
- https://your-account.tulip.co/
OR - https://your-account.dmgmori-tulip.com/
OR - https://your-account.tulip-serendie.com/
Outgoing access to Custom Widgets:
- *.tulip-custom-widgets.com
OR - *.dmgmori-tulip-custom-widgets.com
Outgoing access to content delivery network (CDN):
Outgoing access for live chat support:
- https://api-iam.intercom.io/
- https://nexus-websocket-a.intercom.io/
- *.zopim.com (port 80 and 443)
- If wildcards are not allowed, please provide access for the following subdomains:
- chat-api.zopim.com
- ccapi-larboard.zopim.com
- chat-polaris-api.zopim.com
- chat-polaris-larboard.zopim.com
- widget-mediator.zopimdashboard-mediator.zopim.com
- chat-polaris.zopim.com
- If wildcards are not allowed, please provide access for the following subdomains:
Outgoing access for onboarding interactions:
Tulip Player
To download, use, and update the Tulip Player, we require the following:
Requirements
Outgoing access to Factory:
- https://your-account.tulip.co/
OR - https://your-account.dmgmori-tulip.com/
OR - https://your-account.tulip-serendie.com/
Outgoing access to Custom Widgets:
- *.tulip-custom-widgets.com
OR - *.dmgmori-tulip-custom-widgets.com
Outgoing access to content delivery network (CDN):
Outgoing access for Player updates:
For customers using Tulip Player within China, we recommend following the Tulip Player Enterprise Deployments and granting access to the relevant download URLs.
Tulip Edge Devices
To use and update Tulip's hardware, we require the following:
Requirements
Outgoing access to Factory:
- https://your-account.tulip.co/
OR - https://your-account.dmgmori-tulip.com/
OR - https://your-account.tulip-serendie.com/
Outgoing access for Edge Device updates:
Outgoing access for date time synchronization:
- ntp://[0-3].north-america.pool.ntp.org
Tulip Cloud Connector Host
To use the Tulip Cloud Connector Host to connect to a database, API, or OPC UA server, we require the following:
Requirements
Incoming access to Factory:
- https://your-account.tulip.co/
OR - https://your-account.dmgmori-tulip.com/
OR - https://your-account.tulip-serendie.com/
Tulip On Premise Connector Host
To use the self-hosted Docker Tulip Connector Host to connect to a database, API, or OPC UA server, we require the following:
Requirements
Outgoing access to Factory:
- https://your-account.tulip.co/
OR - https://your-account.dmgmori-tulip.com/
OR - https://your-account.tulip-serendie.com/
Outgoing access for updates:
Outgoing access for connections:
- All third-party services to be connected to Tulip.
Revision history (since February 2025)
| Area of Revision | Date of Revision | Revision Summary |
|---|---|---|
| Network stability and data integrity requirements for Tulip cloud deployments | 07/29/2026 | Moved advanced topics to a separate article. |
| IP Allowlist | 07/29/2026 | Added IP allowlist for garden with identifier apac-35* |
| Tulip Player | 02/13/2026 | Added reference for Tulip player usage from within China |
| IP Allowlist | 01/14/2026 | Added IP allowlist for garden with identifier us-34* |
|
11/18/2025 | New sections and information |
| Admin Interface (Web Browser) & IP Allowlist | 10/23/2025 | Updated IP allowlist based on garden identifiers & removed outdated CSV import requirements |
| Allowlist / Region: us | 9/29/2025 | Added "20.84.216.50" to Connector Host addresses in us region |
| Allowlist / Region: us | 9/13/2025 | One Connector Host address updated from ‘20.84.217.148/31’ To ‘20.84.217.148/30’ |
| Admin Interface (Web Browser) & Tulip Player | 4/17/2025 | Improved highlighting of requirement for Custom Widgets |
| Allowlist / Region: apac | 2/27/2025 | - Instance & Connector Host: Additional I.P. addresses. - Additional URL in Asset Storage |
| Admin Interface (Web Browser) & Tulip Player | 2/12/2025 | New requirement for Custom Widgets |
Did you find what you were looking for?
You can also head to community.tulip.co to post your question or see if others have faced a similar question!
