This article lists the IP addresses and domains required to configure a firewall, proxy, or allowlist so that Phrase functions correctly on a restricted network. Phrase traffic uses HTTPS over TCP port 443 unless specified differently.
This article applies when:
-
Phrase connects to internal systems, such as integrations, webhooks, or MT engines hosted behind a firewall. Allow the IP addresses below in inbound rules.
-
Internal systems connect to Phrase, and outbound traffic is restricted. Allow the Phrase domains below in outbound rules.
Networks without traffic restrictions require no additional configuration.
The Phrase Platform is fully co-hosted on AWS, with the exception of Phrase Studio, which is listed separately below.
Connections initiated by the Phrase Platform, such as integrations and webhooks, originate from static IP addresses. Allow the addresses for the region that hosts the Phrase account.
Phrase EU
List of IP addresses: phrase-platform-ip-addresses-eu.yaml
Phrase US
List of IP addresses: phrase-platform-ip-addresses-us.yaml
To verify that a webhook request genuinely originates from Phrase, use webhook security tokens rather than relying on the source IP address alone.
Connections From Internal Systems to Phrase
The Phrase Platform is served through CDN distributions and load balancers that use dynamic IP addresses, so no stable inbound IP list is published. Allow traffic by domain instead:
|
Domain |
Notes |
|---|---|
|
|
Covers the general Phrase Platform across multiple subdomains, for example, studio.us.phrase.com. |
|
|
Legacy domain used for Phrase TMS. |
|
|
Legacy domain used for Phrase Strings. |
Phrase domains may resolve via CNAME to AWS-managed hostnames, for example *.cloudfront.net. Configure rules against the Phrase domain name. The resolved targets are not stable and should not be allowlisted directly.
Tip
If a firewall does not support domain-based (FQDN) rules, route requests through an internal proxy server and allow the proxy's IP address instead.
Changes to This List
The addresses and domains on this page can change without prior notice as Phrase maintains the availability, performance, and stability of the Phrase Platform. Review this page and the linked files periodically.