Keep Your Static IP When Leaving Heroku
Your Heroku static IPs belong to the add-on or Private Space that issued them, so plan the allowlist move before you migrate. Add your Fixedmark IP pair to every partner allowlist, run both paths in parallel, then move the app to Railway, Render, Fly.io, or Vercel and remove the old IPs.
Where your Heroku static IP comes from
Heroku's Common Runtime has no static outbound IP. Teams that need one use either a Private Space, an Enterprise feature with four stable outbound IPs per space (three active at a time), or a proxy add-on such as Fixie, QuotaGuard, or Proximo. In both cases the IP is tied to that product, not to your app's code.
Some add-on vendors let you keep their IPs after you leave Heroku. Per Fixie's Heroku listing, its IPs stay with you off Heroku as long as you keep subscribing. Per QuotaGuard's pricing page, your QuotaGuard IPs, configuration, and connection URL come with you. If that suits you, staying with your current vendor is the shortest path. If you want a dedicated pair at a lower tier or one subscription for HTTP and SOCKS5, plan a switch.
The parallel allowlist method
IP addresses cannot move between providers, so a switch always means a new allowlist entry. The safe way is to add before you remove. Each partner holds both the old and new IPs for a short overlap, so no request is ever sent from an address the partner does not know.
Start with an inventory. Search your codebase for proxy environment variables such as FIXIE_URL, QUOTAGUARDSTATIC_URL, or PROXIMO_URL, and list every destination that goes through them. Then list the partners who hold your IPs: banks, payment gateways, Salesforce orgs, database firewalls, and SFTP vendors. Allowlist changes at banks can take weeks, so send those requests first.
Choosing where to go
Fixedmark works from any platform that can make outbound HTTPS or TCP connections. Railway, Render, and Fly.io run long-lived processes, so both the proxy URL and the bm tunnel CLI work there. Vercel and Netlify functions can use the proxy URL and SOCKS5 drivers. Each integration guide covers the platform's own static IP option and when to choose it instead.
Migrate your static IP off Heroku
Do the IP switch while still on Heroku, then move platforms with the new IPs already trusted.
Fixedmark is in early access. Proxy URLs are issued at launch. Join early access to get yours when your region opens.
- 1Inventory destinations and partnersList every host your app reaches through the current proxy, and every partner, firewall, or database that allowlists your IPs.
- 2Add your Fixedmark pair everywhereSend both new IPs to each partner and ask them to add, not replace. Keep the old IPs listed.
- 3Switch the proxy on HerokuSet
FIXEDMARK_PROXY_URLwithheroku config:setand point your HTTP clients at it. Check connection logs for each destination. - 4Move the appDeploy to the new platform with the same environment variable. Partners already trust the new IPs.
- 5Remove the old IPsAfter a quiet period, ask partners to remove the old addresses and cancel the old add-on.
// npm install undici (undici 8 needs Node.js 22.19+)
import { fetch, ProxyAgent } from "undici";
// FIXEDMARK_PROXY_URL=https://APP_ID:TOKEN@mum.egress.fixedmark.com:443
const proxy = new ProxyAgent(process.env.FIXEDMARK_PROXY_URL);
const res = await fetch("https://api.partner.example/v1/orders", {
dispatcher: proxy,
headers: { authorization: `Bearer ${process.env.PARTNER_API_KEY}` },
});
console.log(res.status, await res.json());# pip install requests (urllib3 1.26+ for an https:// proxy URL)
import os
import requests
proxy = os.environ["FIXEDMARK_PROXY_URL"]
proxies = {"http": proxy, "https": proxy}
res = requests.get(
"https://api.partner.example/v1/orders",
proxies=proxies,
headers={"Authorization": f"Bearer {os.environ['PARTNER_API_KEY']}"},
timeout=15,
)
print(res.status_code, res.json())package main
import (
"fmt"
"net/http"
"net/url"
"os"
"time"
)
func main() {
proxyURL, err := url.Parse(os.Getenv("FIXEDMARK_PROXY_URL"))
if err != nil {
panic(err)
}
client := &http.Client{
Transport: &http.Transport{Proxy: http.ProxyURL(proxyURL)},
Timeout: 15 * time.Second,
}
res, err := client.Get("https://api.partner.example/v1/orders")
if err != nil {
panic(err)
}
defer res.Body.Close()
fmt.Println(res.Status)
}# Prints the IP the destination sees. Repeat it: each new connection
# leaves from one of the two IPs in your pair.
curl --proxy "$FIXEDMARK_PROXY_URL" https://fixedmark.com/api/ipSources
Checked October 2026. Confirm current details on the vendor's site before you decide. Prices and limits change.
Related guides
- IntegrationHerokuStatic outbound IPs for Common Runtime dynos, and a pair that moves with you.
- IntegrationRailwayA dedicated IP pair for Railway services when shared static IPs are not enough.
- IntegrationRenderAllowlist two IPs that are yours instead of Render's shared regional ranges.
- ComparisonFixie alternativeFixie's published plans and regions next to Fixedmark's planned dedicated IP pairs, Asia regions, and single HTTP plus SOCKS5 plan.
- ComparisonQuotaGuard alternativeQuotaGuard Static and Shield published plans next to Fixedmark's planned $29 dedicated pair.
- ComparisonProximo alternativeProximo's Heroku add-on plans and single-IP model next to Fixedmark's planned dedicated pair that works on any platform.
Frequently asked questions
Can I keep my Heroku static IP after migrating?
It depends on who issued it. Private Space IPs stay with Heroku. Some proxy add-ons, such as Fixie and QuotaGuard, say their IPs can follow you off Heroku. Check with your vendor.
Can I transfer my existing IPs to Fixedmark?
No. IP addresses belong to the provider that owns them. Add your Fixedmark pair alongside the old IPs, then remove the old ones after cutover.
How long should both IP sets stay allowlisted?
Keep both until every destination shows traffic from the new IPs in your connection logs, typically a week or two.
Does Heroku Common Runtime have static outbound IPs?
No. Static outbound IPs on Heroku require Private Spaces, an Enterprise feature with four stable outbound IPs per space, or a proxy add-on.
Make it fixed.
Fixedmark is in early access. Join the list to get dedicated static IPs when your region opens.