Network & Allowlisting

The IP addresses Spot's webhooks come from and the addresses of the Spot API, for firewalls and allowlists.

Verifying webhooks come from Spot

If you want to be sure a webhook came from Spot, check its signature, not its IP address. Every webhook is signed with HMAC-SHA256 in the X-Spot-Signature header. See Authenticating Webhook Payloads.

Allowing Spot webhooks through your firewall

Spot sends webhooks from these addresses:

  • 3.14.235.94
  • 3.20.157.155
  • 3.13.111.19
🚧

Production and Sandbox share these addresses

You can't use the source IP to tell Spot's environments apart, and the webhook payload has no environment field. Register a different webhook URL for each environment, and use the URL a webhook arrives on to tell which environment sent it.

Allowlisting these addresses is fine, but it doesn't prove a request came from Spot. Always verify the signature too.

Reaching the Spot API from a restricted network

If your outbound traffic is restricted, allow the API host for each environment you use:

EnvironmentHostAddresses
Productionapi.getspot.com166.117.75.146, 166.117.238.218
Sandboxapi.sandbox.getspot.com15.197.171.153, 99.83.249.214

Allow by hostname if your tooling supports it. If it can only match IP addresses (for example, AWS security
groups), allow both addresses for each environment.

These addresses are stable

All of the addresses on this page are fixed. If any of them ever needs to change, we will tell you in
advance, before the change happens.