Skip to main content
Corporate firewalls, secure web gateways, and forward proxies protect company networks by filtering outbound traffic. To ensure your team can access the web interface, stream chat responses in real time, and upload documents without disruption, your network appliances must permit connections to Omnifact cloud services.
Scope: This guide applies to Omnifact Cloud. It does not apply to private on-premise installations or custom domain deployments.

Required Hostnames and Ports

The simplest and most reliable configuration is to allow outbound traffic to *.omnifact.ai and omnifact.ai on TCP port 443 (HTTPS). If your firewall or proxy policy does not support wildcard domains, configure explicit rules for the following hostnames:
If your organization uses Single Sign-On (SSO), ensure your network policies also permit outbound access to your identity provider, such as Microsoft Entra ID, Okta, or Google Workspace.

Resolving Common Network and Proxy Blockers

Even when ports and hostnames are open, specific inspection features on corporate proxies can disrupt platform functionality.

WebSocket Connections

Chat responses stream in real time over a persistent WebSocket connection to api.omnifact.ai.
  • Your proxy or next-generation firewall must allow the HTTP Upgrade: websocket header.
  • If WebSockets are blocked or improperly intercepted, the web interface loads, but responses fail to arrive or experience significant delays.

TLS/SSL Inspection

Deep packet inspection (SSL decryption) can break encrypted authentication and streaming handshakes:
  • Exclude sso-auth.omnifact.ai from TLS inspection. Re-signing certificates during SAML flows often causes identity provider authentication to fail.
  • If users still experience dropped chat streams or failed document uploads, exclude chat.omnifact.ai and api.omnifact.ai from TLS inspection as well.

Response Streaming and Buffering

Omnifact delivers responses incrementally as tokens generate:
  • Services such as Published Spaces and the AI Gateway stream data from connect.omnifact.ai using HTTP chunked transfer encoding (Server-Sent Events).
  • Configure your proxy not to buffer streaming responses and to avoid prematurely closing long-lived idle connections.
Server-to-server API integrations only require access to connect.omnifact.ai. If developers access the interactive API reference at connect.omnifact.ai/docs, ensure your network also permits content from cdn.jsdelivr.net.

IP Address Limitations

Omnifact does not provide static IP addresses for cloud services. All incoming traffic routes through Cloudflare’s globally distributed edge network, which means the IP addresses behind each hostname change dynamically. Always allow traffic by hostname rather than IP address whenever possible. If your firewall strictly requires IP-based filtering, you can permit Cloudflare’s published IP ranges.
Cloudflare IP ranges are shared across all Cloudflare customers worldwide. Allowing these IP ranges provides much broader network access than allowing Omnifact hostnames directly. Use hostname allowlists whenever your security policy permits.

Verifying Network Connectivity

Once your IT team updates firewall and proxy rules, verify the setup from a computer on the corporate network:
1

Sign in to the web app

Open https://chat.omnifact.ai in your browser and sign in using your standard credentials or Single Sign-On.
2

Send a test message

Start a new chat and send a prompt. Confirm that the response streams smoothly in real time without pausing or timing out.
3

Upload an attachment

Attach a small document or image to the conversation. Confirm that the file uploads successfully and can be accessed within the chat.
If access worked during initial setup but suddenly stops, check whether your firewall rule was created with a temporary exception or lease that has expired.

Contacting Support

If your team continues to experience connection issues after applying these rules, contact our support team at support@omnifact.ai. To help us resolve the issue quickly, please include:
  • The exact date, time, and timezone when the issue occurred.
  • The specific hostname or URL that was blocked.
  • The error code or message displayed by your browser, proxy, or firewall.