Render Static IP: Dedicated Outbound IP Pair
By default, Render services send outbound traffic from IP ranges shared by every Render service in the same region, so allowlisting them admits other customers too. Render sells Dedicated IPs for $100 per month per set on Pro workspaces and above. Fixedmark gives the calls that need a fixed source a dedicated pair through a proxy URL.
Why Render's outbound IP is shared
Render lists each region's outbound IP ranges on the service page under Connect, then Outbound. Those ranges are stable, but per Render's docs they are shared by all services in that region. If you allowlist them on a partner API or database, any other Render customer in the region can reach it from the same addresses.
Security reviews flag this quickly. A bank, broker, or enterprise customer usually wants addresses that identify your company, not a hosting provider's region.
Render Dedicated IPs: what it costs
Render's Dedicated IPs add-on costs $100 per month per set on Pro and Scale workspaces, with custom pricing on Enterprise. It is not available on Hobby. Per Render's docs, a set gives you 3 static IPv4 addresses in one region, a workspace can have up to 4 sets by default, and every service type except static sites uses them.
If all your outbound traffic runs on Render in one region and you want no client changes, the add-on is the most direct route. A Fixedmark pair costs less at planned pricing, also works from Vercel, Railway, or a laptop, and includes connection logs that show which calls the partner rejected.
Sources for Render pricing
Checked October 2026. Confirm current details on the vendor's site before you decide. Prices and limits change.
Set up a static IP on Render
Render services, workers, and cron jobs are containers you control, so both the HTTPS proxy and the SOCKS5 or tunnel paths work.
Fixedmark is in early access. Proxy URLs are issued at launch. Join early access to get yours when your region opens.
Before you start
- A Render web service, background worker, or cron job on any workspace plan.
- A Fixedmark proxy URL (
https://APP_ID:TOKEN@mum.egress.fixedmark.com:443) and the two IPs of your pair. Both are issued at launch. Join early access to get them. - For databases: the SOCKS5 URL (
socks5h://APP_ID:TOKEN@mum.egress.fixedmark.com:1080) or thebm tunnelCLI. - Access to the partner's or database's allowlist, or a contact who can add two IPv4 addresses for you.
Steps
- 1Create an environment groupIn the Render dashboard, create an environment group with
FIXEDMARK_PROXY_URL(andFIXEDMARK_SOCKS_URLfor databases). Link it to every service that calls the allowlisted destination. - 2Configure the HTTP clientPass the proxy URL to the client that calls the partner. Use the snippet for your runtime below.
- 3Redeploy and check the egress IPOpen the service's Shell tab and run the curl check below. It should print one of your Fixedmark IPs.
- 4Replace Render's ranges on the allowlistAdd both Fixedmark IPs, confirm traffic works, then ask the partner to remove Render's shared regional ranges.
// npm install undici (undici 8 needs Node.js 22.19+)
import { fetch, ProxyAgent } from "undici";
// FIXEDMARK_PROXY_URL=https://APP_ID:TOKEN@mum.egress.fixedmark.com:443
const proxy = new ProxyAgent(process.env.FIXEDMARK_PROXY_URL);
const res = await fetch("https://api.partner.example/v1/orders", {
dispatcher: proxy,
headers: { authorization: `Bearer ${process.env.PARTNER_API_KEY}` },
});
console.log(res.status, await res.json());# pip install requests (urllib3 1.26+ for an https:// proxy URL)
import os
import requests
proxy = os.environ["FIXEDMARK_PROXY_URL"]
proxies = {"http": proxy, "https": proxy}
res = requests.get(
"https://api.partner.example/v1/orders",
proxies=proxies,
headers={"Authorization": f"Bearer {os.environ['PARTNER_API_KEY']}"},
timeout=15,
)
print(res.status_code, res.json())package main
import (
"fmt"
"net/http"
"net/url"
"os"
"time"
)
func main() {
proxyURL, err := url.Parse(os.Getenv("FIXEDMARK_PROXY_URL"))
if err != nil {
panic(err)
}
client := &http.Client{
Transport: &http.Transport{Proxy: http.ProxyURL(proxyURL)},
Timeout: 15 * time.Second,
}
res, err := client.Get("https://api.partner.example/v1/orders")
if err != nil {
panic(err)
}
defer res.Body.Close()
fmt.Println(res.Status)
}SDKs that do not use fetch (the Stripe and Salesforce Node SDKs, got, axios) accept an HTTP agent. Pass new HttpsProxyAgent(process.env.FIXEDMARK_PROXY_URL) from the https-proxy-agent package, which supports https:// proxy URLs. With axios, also set proxy: false so it does not apply its own proxy logic. undici 8 needs Node 22.19 or later. On older Node, install undici@7.
Verify the egress IP on Render
Check the IP before you send it to a partner. Paid instance types have a Shell tab in the dashboard where you can run curl. On instance types without shell access, deploy the Node.js or Python check as a one-off cron job. The endpoint https://fixedmark.com/api/ip returns the caller's IP as plain text, and the What's my IP tool shows the same thing in a browser.
The proxied call should print one of your two Fixedmark IPs every time. The direct call should print a different address. If both print the same platform IP, the client is not using the proxy.
# Needs curl 7.52 or later for an https:// proxy URL.
# Prints the IP the destination sees. Run it a few times:
# you should only ever see the two IPs of your pair.
curl -sS --proxy "$FIXEDMARK_PROXY_URL" https://fixedmark.com/api/ip
# Same check over SOCKS5, the path database drivers use.
curl -sS --proxy "$FIXEDMARK_SOCKS_URL" https://fixedmark.com/api/ip
# Without the proxy, for comparison. This is the platform's own IP.
curl -sS https://fixedmark.com/api/ip// A temporary route or script that reports the egress IP.
// Remove it after you have checked.
import { fetch, ProxyAgent } from "undici";
const proxy = new ProxyAgent(process.env.FIXEDMARK_PROXY_URL);
const viaProxy = await fetch("https://fixedmark.com/api/ip", { dispatcher: proxy });
const direct = await fetch("https://fixedmark.com/api/ip");
console.log({
fixedmark: (await viaProxy.text()).trim(),
platform: (await direct.text()).trim(),
});import os
import requests
proxy = os.environ["FIXEDMARK_PROXY_URL"]
via = requests.get("https://fixedmark.com/api/ip", proxies={"https": proxy}, timeout=10)
direct = requests.get("https://fixedmark.com/api/ip", timeout=10)
print({"fixedmark": via.text.strip(), "platform": direct.text.strip()})Databases: Postgres, MySQL, and MongoDB
Database drivers do not speak HTTP CONNECT, so the proxy URL above does not cover them. On Render you have two options. Drivers with SOCKS5 support can use FIXEDMARK_SOCKS_URL directly: the MongoDB Node.js driver accepts proxyHost and proxyPort options, and Go's pgx accepts a SOCKS5 dialer. For any other driver, run the bm tunnel CLI (planned for launch) before your app starts, for example in the start command bm tunnel 5432:db.example.com:5432 & npm start, then point the driver at 127.0.0.1.
TLS to the database stays end to end. Fixedmark forwards encrypted bytes and never sees your queries. If your driver verifies the server certificate, keep the real database hostname as the TLS server name when you connect through the local tunnel.
- MongoDB Atlas: add both Fixedmark IPs to the project's IP Access List. See MongoDB Atlas allowlisting.
- AWS RDS, Cloud SQL, and self-hosted Postgres or MySQL: add both IPs as /32 entries. See Postgres and MySQL allowlists.
# Forward local port 5432 to the database through your Fixedmark IPs.
# bm tunnel is planned for launch; flags are not final.
bm tunnel 5432:db.example.com:5432 &
# Point the driver at the local end of the tunnel.
DATABASE_URL="postgres://app:secret@127.0.0.1:5432/app?sslmode=require"// npm install mongodb socks
import { MongoClient } from "mongodb";
// FIXEDMARK_SOCKS_URL=socks5h://APP_ID:TOKEN@mum.egress.fixedmark.com:1080
const socks = new URL(process.env.FIXEDMARK_SOCKS_URL);
const client = new MongoClient(process.env.MONGODB_URI, {
proxyHost: socks.hostname,
proxyPort: Number(socks.port),
proxyUsername: decodeURIComponent(socks.username),
proxyPassword: decodeURIComponent(socks.password),
});
await client.connect();import (
"context"
"net/url"
"os"
"github.com/jackc/pgx/v5/pgxpool"
"golang.org/x/net/proxy"
)
func connect(ctx context.Context) (*pgxpool.Pool, error) {
u, err := url.Parse(os.Getenv("FIXEDMARK_SOCKS_URL"))
if err != nil {
return nil, err
}
pw, _ := u.User.Password()
dialer, err := proxy.SOCKS5("tcp", u.Host,
&proxy.Auth{User: u.User.Username(), Password: pw}, proxy.Direct)
if err != nil {
return nil, err
}
cfg, err := pgxpool.ParseConfig(os.Getenv("DATABASE_URL"))
if err != nil {
return nil, err
}
cfg.ConnConfig.DialFunc = dialer.(proxy.ContextDialer).DialContext
return pgxpool.NewWithConfig(ctx, cfg)
}Common errors and fixes
The partner still sees a Render IP after you linked the env group
Env group changes reach a service on its next deploy. Trigger a manual deploy, then run the IP check again.
407 Proxy Authentication Required
The proxy did not get valid credentials. Check that the env var holds the full URL with APP_ID:TOKEN@, with no quotes or trailing newline. If the token contains @, :, or /, URL-encode it. Some clients drop credentials from the URL: pass them separately (Deno's basicAuth, axios proxy.auth) or switch to undici's ProxyAgent, which reads them from the URL.
TLS errors to the proxy: wrong version number, EPROTO, Proxy CONNECT aborted, or unable to connect to proxy
The client does not support an https:// proxy URL and is speaking plain HTTP to port 443. Upgrade it: curl 7.52+, urllib3 1.26+ (requests), httpx 0.26+, undici ProxyAgent, Go 1.10+. In Ruby, use Typhoeus: Net::HTTP and Faraday's default adapter cannot tunnel HTTPS through a TLS proxy. For older axios releases, set proxy: false and pass https-proxy-agent as httpsAgent. Java's built-in HttpClient cannot speak TLS to a proxy at all. If you cannot upgrade, use the SOCKS5 URL.
ETIMEDOUT or ECONNRESET to the partner, or a 403 from the partner
The proxy connected, but the destination dropped you. Usually only one IP of the pair is on the allowlist, or the partner has not applied the change yet. Add both IPs. If a destination allowlist is set on your Fixedmark token, check the host and port are on it.
The IP check prints the platform's IP, not a Fixedmark IP
The request went direct. Node's built-in fetch ignores HTTPS_PROXY unless NODE_USE_ENV_PROXY=1 is set (Node 22.21+ and 24+). Many SDKs ignore proxy env vars too. Pass the proxy to the client explicitly, as in the snippets above.
429 or 407 with an X-Proxy-Error: quota_exceeded header
Planned behavior when you pass your plan's soft limit. Check usage in the dashboard or raise the plan.
Database driver has no proxy option
node-postgres, mysql2, psycopg, and most ORMs cannot use an HTTP proxy. Use a SOCKS5-capable driver with FIXEDMARK_SOCKS_URL, or run bm tunnel where the platform allows a second process.
Gotchas on Render
Render's private network between your own services is unaffected. Only traffic you send through the proxy uses the Fixedmark pair.
- Static sites have no server-side code, so they have no outbound traffic to route.
- Render Postgres is reached over Render's network. You only need the tunnel for external databases.
- Free instances spin down when idle. A
bm tunnelprocess in the start command restarts with the service.
Related guides
- Use casePartner API allowlistingGive Salesforce, SOAP vendors, and payment gateways one dedicated IP pair to allowlist, wherever your code runs.
- Use caseMongoDB AtlasReplace 0.0.0.0/0 in your Atlas IP access list with two dedicated IPs, using the Node driver's SOCKS5 support.
- Use caseBank and UPI APIsWhitelist one dedicated IP pair with your bank, UPI partner bank, or GSP, then deploy on Vercel or Railway without re-whitelisting.
- IntegrationRailwayA dedicated IP pair for Railway services when shared static IPs are not enough.
- IntegrationHerokuStatic outbound IPs for Common Runtime dynos, and a pair that moves with you.
Frequently asked questions
Does Render have static outbound IPs?
Render publishes stable outbound IP ranges per region, but they are shared by all services in that region. Dedicated IPs are a paid add-on at $100 per month per set of 3 IPv4 addresses on Pro and Scale workspaces.
Is it safe to allowlist Render's regional outbound ranges?
It works, but any Render service in the same region can connect from those ranges. If the destination holds sensitive data or moves money, use dedicated IPs instead.
Can I get a static IP on Render's Hobby workspace?
Render's Dedicated IPs need a Pro workspace or higher. On Hobby, send the calls that need a fixed IP through a static IP proxy URL from an environment group.
Can Render cron jobs use the proxy?
Yes. Cron jobs read the same environment groups as web services. Pass the proxy URL to the HTTP client in the job's script.
Fix your egress IP.
Fixedmark is in early access. Join the list to get a dedicated IP pair for Render when your region opens.