> ## Documentation Index
> Fetch the complete documentation index at: https://docs.omnifact.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Allowing Omnifact in Corporate Networks

> Configure corporate firewalls, proxies, and security appliances to ensure reliable access to Omnifact Cloud.

Corporate firewalls, secure web gateways, and forward proxies protect company networks by filtering outbound traffic. To ensure your team can access the web interface, stream chat responses in real time, and upload documents without disruption, your network appliances must permit connections to Omnifact cloud services.

<Note>
  **Scope:** This guide applies to Omnifact Cloud. It does not apply to private on-premise installations or custom domain deployments.
</Note>

## Required Hostnames and Ports

The simplest and most reliable configuration is to allow outbound traffic to `*.omnifact.ai` and `omnifact.ai` on **TCP port 443 (HTTPS)**.

If your firewall or proxy policy does not support wildcard domains, configure explicit rules for the following hostnames:

| Hostname | Purpose | When Needed |
| :- | :- | :- |
| `chat.omnifact.ai` | Web application interface | Always |
| `api.omnifact.ai` | User authentication, chat processing, and file management | Always |
| `sso-auth.omnifact.ai` | Single Sign-On (SAML) authentication flows | When using [Single Sign-On](/en/platform/team-administration/users) |
| `nango.omnifact.ai` | OAuth authentication for cloud storage integrations | When connecting Google Drive, OneDrive, or SharePoint |
| `connect.omnifact.ai` | Public REST API and AI Gateway endpoints | When using the [AI Gateway](/en/platform/team-administration/ai-gateway) or [Published Spaces](/en/platform/team-administration/published-spaces) |

<Info>
  If your organization uses Single Sign-On (SSO), ensure your network policies also permit outbound access to your identity provider, such as Microsoft Entra ID, Okta, or Google Workspace.
</Info>

## Resolving Common Network and Proxy Blockers

Even when ports and hostnames are open, specific inspection features on corporate proxies can disrupt platform functionality.

### WebSocket Connections

Chat responses stream in real time over a persistent WebSocket connection to `api.omnifact.ai`.

* Your proxy or next-generation firewall must allow the HTTP `Upgrade: websocket` header.
* If WebSockets are blocked or improperly intercepted, the web interface loads, but responses fail to arrive or experience significant delays.

### TLS/SSL Inspection

Deep packet inspection (SSL decryption) can break encrypted authentication and streaming handshakes:

* **Exclude `sso-auth.omnifact.ai` from TLS inspection.** Re-signing certificates during SAML flows often causes identity provider authentication to fail.
* If users still experience dropped chat streams or failed document uploads, exclude `chat.omnifact.ai` and `api.omnifact.ai` from TLS inspection as well.

### Response Streaming and Buffering

Omnifact delivers responses incrementally as tokens generate:

* Services such as [Published Spaces](/en/platform/team-administration/published-spaces) and the [AI Gateway](/en/platform/team-administration/ai-gateway) stream data from `connect.omnifact.ai` using HTTP chunked transfer encoding (Server-Sent Events).
* Configure your proxy not to buffer streaming responses and to avoid prematurely closing long-lived idle connections.

<Info>
  Server-to-server API integrations only require access to `connect.omnifact.ai`. If developers access the interactive API reference at `connect.omnifact.ai/docs`, ensure your network also permits content from `cdn.jsdelivr.net`.
</Info>

## IP Address Limitations

Omnifact does not provide static IP addresses for cloud services. All incoming traffic routes through Cloudflare's globally distributed edge network, which means the IP addresses behind each hostname change dynamically.

Always allow traffic by **hostname** rather than IP address whenever possible.

If your firewall strictly requires IP-based filtering, you can permit Cloudflare's published [IP ranges](https://www.cloudflare.com/ips/).

<Warning>
  Cloudflare IP ranges are shared across all Cloudflare customers worldwide. Allowing these IP ranges provides much broader network access than allowing Omnifact hostnames directly. Use hostname allowlists whenever your security policy permits.
</Warning>

## Verifying Network Connectivity

Once your IT team updates firewall and proxy rules, verify the setup from a computer on the corporate network:

<Steps>
  <Step title="Sign in to the web app">
    Open `https://chat.omnifact.ai` in your browser and sign in using your standard credentials or Single Sign-On.
  </Step>

  <Step title="Send a test message">
    Start a new chat and send a prompt. Confirm that the response streams smoothly in real time without pausing or timing out.
  </Step>

  <Step title="Upload an attachment">
    Attach a small document or image to the conversation. Confirm that the file uploads successfully and can be accessed within the chat.
  </Step>
</Steps>

<Note>
  If access worked during initial setup but suddenly stops, check whether your firewall rule was created with a temporary exception or lease that has expired.
</Note>

## Contacting Support

If your team continues to experience connection issues after applying these rules, contact our support team at [support@omnifact.ai](mailto:support@omnifact.ai). To help us resolve the issue quickly, please include:

* The exact date, time, and timezone when the issue occurred.
* The specific hostname or URL that was blocked.
* The error code or message displayed by your browser, proxy, or firewall.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.