Static IP for Partner API Allowlisting
When a partner API only accepts requests from allowlisted IPs, send those requests through a static egress IP and give the partner that address. Fixedmark provides a dedicated IP pair that works for Salesforce, legacy SOAP vendors, and payment gateways from any serverless or PaaS platform.
Who asks for your IP
IP allowlisting is still a standard control for B2B integrations. You will meet it in places like these:
- Salesforce orgs that limit integration users with profile login IP ranges, or connected apps set to enforce IP restrictions against the org's trusted IP ranges.
- Enterprise and government vendors with SOAP or SFTP endpoints behind a firewall that only opens to named IPs.
- Payment gateways and payout providers that whitelist server IPs for refunds, payouts, or settlement APIs.
- Logistics, insurance, and HR systems whose onboarding checklist includes a field for production IPs.
Why a dedicated pair matters
A shared proxy IP is used by many customers at once. If one of them misbehaves, a partner's security tooling can flag the address for everyone. QuotaGuard has written publicly about Salesforce flagging shared proxy IPs as an anonymizing proxy until they were recognized. A dedicated pair limits that exposure to your own traffic, although no provider can promise a partner will never flag an address.
Two addresses also give you high availability. Partners add both, and traffic keeps flowing if one proxy node is out of service. Allowlist forms rarely object to a second IP, and asking for both up front saves a second ticket later.
Debugging allowlist errors
Partner APIs rarely explain a rejection. A 403, a TLS reset, or a timeout can all mean the IP is not on the list. Fixedmark's connection logs show the destination host, SNI, bytes, egress IP, and result for every connection, so you can tell a firewall drop apart from an application error and send the partner the exact IP and timestamp.
Allowlist a static IP with a partner
Route only partner traffic through the proxy. Everything else can keep its direct path.
Fixedmark is in early access. Proxy URLs are issued at launch. Join early access to get yours when your region opens.
- 1Create a dedicated pairPick the region closest to the partner's API, for example Virginia for a US vendor or Frankfurt for an EU one.
- 2Send both IPs to the partnerSubmit both addresses in the onboarding form or support ticket. For Salesforce, add each as a range with the same start and end address, in the integration user's profile login IP ranges or the org's trusted IP ranges.
- 3Store the proxy URLSet
FIXEDMARK_PROXY_URLas an environment variable on your platform. - 4Use a proxied client for partner callsCreate one HTTP client with the proxy and use it for partner requests only. SOAP libraries built on standard HTTP clients accept the same proxy settings.
- 5Restrict and verifyAdd a destination allowlist for the partner's hostname and check the connection logs after the first request.
// npm install undici (undici 8 needs Node.js 22.19+)
import { fetch, ProxyAgent } from "undici";
// FIXEDMARK_PROXY_URL=https://APP_ID:TOKEN@mum.egress.fixedmark.com:443
const proxy = new ProxyAgent(process.env.FIXEDMARK_PROXY_URL);
const res = await fetch("https://api.partner.example/v1/orders", {
dispatcher: proxy,
headers: { authorization: `Bearer ${process.env.PARTNER_API_KEY}` },
});
console.log(res.status, await res.json());# pip install requests (urllib3 1.26+ for an https:// proxy URL)
import os
import requests
proxy = os.environ["FIXEDMARK_PROXY_URL"]
proxies = {"http": proxy, "https": proxy}
res = requests.get(
"https://api.partner.example/v1/orders",
proxies=proxies,
headers={"Authorization": f"Bearer {os.environ['PARTNER_API_KEY']}"},
timeout=15,
)
print(res.status_code, res.json())package main
import (
"fmt"
"net/http"
"net/url"
"os"
"time"
)
func main() {
proxyURL, err := url.Parse(os.Getenv("FIXEDMARK_PROXY_URL"))
if err != nil {
panic(err)
}
client := &http.Client{
Transport: &http.Transport{Proxy: http.ProxyURL(proxyURL)},
Timeout: 15 * time.Second,
}
res, err := client.Get("https://api.partner.example/v1/orders")
if err != nil {
panic(err)
}
defer res.Body.Close()
fmt.Println(res.Status)
}# Prints the IP the destination sees. Repeat it: each new connection
# leaves from one of the two IPs in your pair.
curl --proxy "$FIXEDMARK_PROXY_URL" https://fixedmark.com/api/ipSources
Checked October 2026. Confirm current details on the vendor's site before you decide. Prices and limits change.
Related guides
- Use caseBank and UPI APIsWhitelist one dedicated IP pair with your bank, UPI partner bank, or GSP, then deploy on Vercel or Railway without re-whitelisting.
- Use caseSFTP allowlistingReach bank, payroll, and EDI SFTP servers that only accept allowlisted IPs, through SOCKS5 or a local tunnel.
- Use caseHeroku migrationMove off Heroku without breaking partner allowlists by running both IP sets in parallel during the switch.
- IntegrationVercelFixed egress IPs for Vercel Functions without the $100 per project add-on.
- IntegrationRenderAllowlist two IPs that are yours instead of Render's shared regional ranges.
- ComparisonQuotaGuard alternativeQuotaGuard Static and Shield published plans next to Fixedmark's planned $29 dedicated pair.
Frequently asked questions
How do I give Salesforce a static IP for my app?
Route your API calls through a static egress IP. To block logins from anywhere else, add it to the integration user's profile login IP ranges. Org-wide trusted IP ranges only skip identity verification, unless a connected app enforces IP restrictions. Use the same value for the start and end of each range.
Why do partners ask for two IPs?
Two addresses let the proxy fail over without a new allowlist request. Fixedmark issues a pair for that reason.
Will a SOAP client work through the proxy?
Yes, if the client sends HTTP through a library that supports a proxy, which most do. SOAP over HTTPS passes through as an encrypted CONNECT tunnel.
Do I need dedicated IPs or are shared IPs enough?
Shared IPs are cheaper and fine for low-risk partners. Choose dedicated IPs when the partner is strict about reputation or requires an address unique to you.
Make it fixed.
Fixedmark is in early access. Join the list to get dedicated static IPs when your region opens.