Scope: This guide applies to Omnifact Cloud. It does not apply to private on-premise installations or custom domain deployments.
Required Hostnames and Ports
The simplest and most reliable configuration is to allow outbound traffic to*.omnifact.ai and omnifact.ai on TCP port 443 (HTTPS).
If your firewall or proxy policy does not support wildcard domains, configure explicit rules for the following hostnames:
If your organization uses Single Sign-On (SSO), ensure your network policies also permit outbound access to your identity provider, such as Microsoft Entra ID, Okta, or Google Workspace.
Resolving Common Network and Proxy Blockers
Even when ports and hostnames are open, specific inspection features on corporate proxies can disrupt platform functionality.WebSocket Connections
Chat responses stream in real time over a persistent WebSocket connection toapi.omnifact.ai.
- Your proxy or next-generation firewall must allow the HTTP
Upgrade: websocketheader. - If WebSockets are blocked or improperly intercepted, the web interface loads, but responses fail to arrive or experience significant delays.
TLS/SSL Inspection
Deep packet inspection (SSL decryption) can break encrypted authentication and streaming handshakes:- Exclude
sso-auth.omnifact.aifrom TLS inspection. Re-signing certificates during SAML flows often causes identity provider authentication to fail. - If users still experience dropped chat streams or failed document uploads, exclude
chat.omnifact.aiandapi.omnifact.aifrom TLS inspection as well.
Response Streaming and Buffering
Omnifact delivers responses incrementally as tokens generate:- Services such as Published Spaces and the AI Gateway stream data from
connect.omnifact.aiusing HTTP chunked transfer encoding (Server-Sent Events). - Configure your proxy not to buffer streaming responses and to avoid prematurely closing long-lived idle connections.
Server-to-server API integrations only require access to
connect.omnifact.ai. If developers access the interactive API reference at connect.omnifact.ai/docs, ensure your network also permits content from cdn.jsdelivr.net.IP Address Limitations
Omnifact does not provide static IP addresses for cloud services. All incoming traffic routes through Cloudflare’s globally distributed edge network, which means the IP addresses behind each hostname change dynamically. Always allow traffic by hostname rather than IP address whenever possible. If your firewall strictly requires IP-based filtering, you can permit Cloudflare’s published IP ranges.Verifying Network Connectivity
Once your IT team updates firewall and proxy rules, verify the setup from a computer on the corporate network:1
Sign in to the web app
Open
https://chat.omnifact.ai in your browser and sign in using your standard credentials or Single Sign-On.2
Send a test message
Start a new chat and send a prompt. Confirm that the response streams smoothly in real time without pausing or timing out.
3
Upload an attachment
Attach a small document or image to the conversation. Confirm that the file uploads successfully and can be accessed within the chat.
If access worked during initial setup but suddenly stops, check whether your firewall rule was created with a temporary exception or lease that has expired.
Contacting Support
If your team continues to experience connection issues after applying these rules, contact our support team at support@omnifact.ai. To help us resolve the issue quickly, please include:- The exact date, time, and timezone when the issue occurred.
- The specific hostname or URL that was blocked.
- The error code or message displayed by your browser, proxy, or firewall.