Skip to content
Fixedmark
Use case · Integrations

Static IP for Partner API Allowlisting

When a partner API only accepts requests from allowlisted IPs, send those requests through a static egress IP and give the partner that address. Fixedmark provides a dedicated IP pair that works for Salesforce, legacy SOAP vendors, and payment gateways from any serverless or PaaS platform.

Who asks for your IP

IP allowlisting is still a standard control for B2B integrations. You will meet it in places like these:

  • Salesforce orgs that limit integration users with profile login IP ranges, or connected apps set to enforce IP restrictions against the org's trusted IP ranges.
  • Enterprise and government vendors with SOAP or SFTP endpoints behind a firewall that only opens to named IPs.
  • Payment gateways and payout providers that whitelist server IPs for refunds, payouts, or settlement APIs.
  • Logistics, insurance, and HR systems whose onboarding checklist includes a field for production IPs.

Why a dedicated pair matters

A shared proxy IP is used by many customers at once. If one of them misbehaves, a partner's security tooling can flag the address for everyone. QuotaGuard has written publicly about Salesforce flagging shared proxy IPs as an anonymizing proxy until they were recognized. A dedicated pair limits that exposure to your own traffic, although no provider can promise a partner will never flag an address.

Two addresses also give you high availability. Partners add both, and traffic keeps flowing if one proxy node is out of service. Allowlist forms rarely object to a second IP, and asking for both up front saves a second ticket later.

Debugging allowlist errors

Partner APIs rarely explain a rejection. A 403, a TLS reset, or a timeout can all mean the IP is not on the list. Fixedmark's connection logs show the destination host, SNI, bytes, egress IP, and result for every connection, so you can tell a firewall drop apart from an application error and send the partner the exact IP and timestamp.

Allowlist a static IP with a partner

Route only partner traffic through the proxy. Everything else can keep its direct path.

Fixedmark is in early access. Proxy URLs are issued at launch. Join early access to get yours when your region opens.

  1. 1
    Create a dedicated pairPick the region closest to the partner's API, for example Virginia for a US vendor or Frankfurt for an EU one.
  2. 2
    Send both IPs to the partnerSubmit both addresses in the onboarding form or support ticket. For Salesforce, add each as a range with the same start and end address, in the integration user's profile login IP ranges or the org's trusted IP ranges.
  3. 3
    Store the proxy URLSet FIXEDMARK_PROXY_URL as an environment variable on your platform.
  4. 4
    Use a proxied client for partner callsCreate one HTTP client with the proxy and use it for partner requests only. SOAP libraries built on standard HTTP clients accept the same proxy settings.
  5. 5
    Restrict and verifyAdd a destination allowlist for the partner's hostname and check the connection logs after the first request.
// npm install undici  (undici 8 needs Node.js 22.19+)
import { fetch, ProxyAgent } from "undici";

// FIXEDMARK_PROXY_URL=https://APP_ID:TOKEN@mum.egress.fixedmark.com:443
const proxy = new ProxyAgent(process.env.FIXEDMARK_PROXY_URL);

const res = await fetch("https://api.partner.example/v1/orders", {
  dispatcher: proxy,
  headers: { authorization: `Bearer ${process.env.PARTNER_API_KEY}` },
});
console.log(res.status, await res.json());

Sources

Checked October 2026. Confirm current details on the vendor's site before you decide. Prices and limits change.

Frequently asked questions

How do I give Salesforce a static IP for my app?

Route your API calls through a static egress IP. To block logins from anywhere else, add it to the integration user's profile login IP ranges. Org-wide trusted IP ranges only skip identity verification, unless a connected app enforces IP restrictions. Use the same value for the start and end of each range.

Why do partners ask for two IPs?

Two addresses let the proxy fail over without a new allowlist request. Fixedmark issues a pair for that reason.

Will a SOAP client work through the proxy?

Yes, if the client sends HTTP through a library that supports a proxy, which most do. SOAP over HTTPS passes through as an encrypted CONNECT tunnel.

Do I need dedicated IPs or are shared IPs enough?

Shared IPs are cheaper and fine for low-risk partners. Choose dedicated IPs when the partner is strict about reputation or requires an address unique to you.

Make it fixed.

Fixedmark is in early access. Join the list to get dedicated static IPs when your region opens.