Blaze

Network Allowlist Settings for Using Blaze on a Corporate Network

Corporate firewalls, proxies, web filters, or endpoint security products may block connections required for Blaze sign-in and normal use.

Share the destinations on this page with your IT team or internal help desk if you experience any of the following:

  • The sign-in screen displays a message stating that Blaze cannot connect to the server
  • Blaze works on another network, such as a mobile hotspot, but not on the corporate network
  • Connecting to Salesforce, adding a Skill from GitHub, or updating Blaze fails

Required Network Settings

Allow Blaze to connect to the internet using the following settings.

ItemRequired setting
DirectionOutbound
ProtocolHTTPS
PortTCP 443
Allowlist typeFQDN (domain name), not IP address

Blaze does not require any inbound ports to be opened. Because the IP addresses used by cloud services and download providers may change, allow the FQDNs below instead of fixed IP addresses.

Destinations required for Blaze

DestinationPurpose
auth.igness.aiBlaze authentication
id.igness.aiSign-in and identity flows
blaze-api.igness.aiBlaze API
llm.igness.aiAI features
account.igness.aiAccount, organization, and device management

These are the destinations used by the Blaze production environment. For normal use, start by allowing HTTPS access to all destinations in this table.

Destinations used for GitHub downloads

Blaze uses GitHub when adding Skills from public GitHub repositories. Blaze installations distributed outside the Microsoft Store also use GitHub to check for and download application updates.

DestinationPurpose
api.github.comCheck the latest Blaze version
github.comDownload Blaze updates
codeload.github.comDownload Skill ZIP archives from public GitHub repositories
release-assets.githubusercontent.comDownload files from GitHub Releases
objects.githubusercontent.comDownload files after a GitHub redirect
github-releases.githubusercontent.comDownload GitHub update and release files

To add Skills from GitHub, allow direct connections to codeload.github.com. Application update downloads may redirect to another domain, so in addition to github.com, allow the githubusercontent.com destinations listed in the table. If your organization’s policy supports wildcard entries, you may instead cover GitHub’s content delivery destinations with *.githubusercontent.com.

💡 The Microsoft Store edition does not require the application-update destinations. However, it still requires access to codeload.github.com when adding Skills from GitHub.

Destinations used to connect to Salesforce

When connecting Blaze to a Salesforce org, also allow the destinations required by that org.

DestinationPurpose
login.salesforce.comSign in to a Salesforce production org
test.salesforce.comSign in to a Salesforce sandbox
Your org’s *.my.salesforce.comSalesforce API access after sign-in
Your org’s *.salesforce.comSalesforce instance API access

My Domain and instance URLs vary by Salesforce org. Where possible, allow only the specific FQDNs used by your Salesforce org instead of broad wildcard entries.

If Blaze still cannot connect

  1. Quit Blaze completely, then reopen it.
  2. Retry sign-in or whichever operation failed.
  3. If you use a VPN, follow your organization’s policy and compare the result while connected and disconnected.
  4. Review your security product’s block log for any rejected destinations not listed above.

If the issue continues, contact support and include the following information:

  • The date and time when the error occurred
  • The displayed error message or a screenshot
  • Your operating system and Blaze version
  • Whether the result differs between the corporate network and another network
  • The blocked domain reported by the security product, if available

Do not send secrets such as verification codes, passwords, or access tokens.