apps/docs/content/guides/manage/cloud/egress.mdx
When configuring your firewall or network security groups, you may need to allow traffic from ZITADEL Cloud to your internal infrastructure.
This page lists the static Egress (outgoing) IP addresses used by ZITADEL Cloud regions.
You need to allowlist these IP addresses if you use features where ZITADEL initiates a connection to your systems. This is commonly required for the following scenarios:
If you are federating an external Identity Provider (IdP) that sits behind a firewall:
636 for LDAPS)./.well-known/openid-configuration.token_endpoint.userinfo_endpoint.jwks_uri.metadata.xml or artifact resolution services from an internal SAML IdP.We recommend allowing the IP address corresponding to the region where your ZITADEL instance is hosted.
| Region | Egress IP Address |
|---|---|
| Switzerland | 34.65.158.196 |
| Europe | 34.107.19.72 |
| United States | 34.69.146.246 |
| Australia | 34.87.243.23 |
To find out which region your ZITADEL Cloud instance is running in, check the ZITADEL Customer Portal.
</Callout>