Skip to content
Fixedmark
Use case · File transfer

Static IP for SFTP Allowlisting From Serverless Apps

Banks, payroll providers, retailers, and logistics partners often run SFTP servers that only accept connections from allowlisted IPs. Connect through a static IP pair using SOCKS5 in your SFTP library, or the planned bm tunnel CLI on long-lived services, and give the partner both addresses. SSH encryption and host key checks still run end to end.

Who still asks for an SFTP allowlist

File drops over SFTP are still the norm for batch integrations. The server's firewall usually opens port 22 only to IPs on the partner's list:

  • Bank host-to-host links for payment files, statements, and reconciliation reports.
  • Payroll, benefits, and HR providers that exchange employee files.
  • Retail and logistics EDI exchanges for orders, invoices, and shipment notices.
  • Data vendors and enterprise customers that push or pull nightly exports.

Choose a connection path

SOCKS5 works anywhere, including serverless functions. Node's ssh2 and ssh2-sftp-client accept an already-open socket through the sock option, which you can open with the socks package. Python's paramiko also takes a sock argument, which PySocks can provide. In Go, dial through golang.org/x/net/proxy and pass the connection to ssh.NewClientConn.

The planned bm tunnel CLI forwards a local port to the SFTP server through your Fixedmark IPs. It suits long-lived services on Railway, Render, Fly.io, or a VM, and the sftp command line tool. Set OpenSSH's HostKeyAlias to the real hostname so host key checks still match.

Plan for function time limits

Large file transfers can outlast a serverless function's maximum duration. If your files are big or the partner's server is slow, run transfers from a background worker or a scheduled job on a long-lived service, and keep functions for small files.

This page covers SFTP. Classic FTP and FTPS open separate data connections on other ports, so they need a client that sends both the control and data connections through SOCKS5. Ask the partner whether SFTP is available first.

Allowlist a static IP with an SFTP partner

Keep the existing path working until the partner confirms the new IPs.

Fixedmark is in early access. Proxy URLs are issued at launch. Join early access to get yours when your region opens.

  1. 1
    Create a pair near the serverChoose the region closest to the partner's SFTP host, for example Mumbai for an Indian bank's host-to-host server.
  2. 2
    Send both IPs to the partnerAsk them to allow both addresses on the SFTP port. Send your SSH public key in the same request if they need one.
  3. 3
    Store the SOCKS URLSet FIXEDMARK_SOCKS_URL on your platform. For the tunnel path, the CLI reads its token from its own config.
  4. 4
    Connect through SOCKS5 or the tunnelPass a proxied socket to your SFTP library, or start bm tunnel and connect to the local port with HostKeyAlias set.
  5. 5
    Pin the host key and verifyKeep strict host key checking on. Confirm the first transfer in the connection log, then remove any old allowlist entries.
// npm install ssh2-sftp-client socks
import SftpClient from "ssh2-sftp-client";
import { SocksClient } from "socks";

const socks = new URL(process.env.FIXEDMARK_SOCKS_URL);
const host = "sftp.partner.example";

// Open the TCP connection through your Fixedmark IPs.
const { socket } = await SocksClient.createConnection({
  proxy: {
    host: socks.hostname,
    port: Number(socks.port),
    type: 5,
    userId: decodeURIComponent(socks.username),
    password: decodeURIComponent(socks.password),
  },
  command: "connect",
  destination: { host, port: 22 },
});

// SSH runs over that socket, end to end with the partner.
const sftp = new SftpClient();
await sftp.connect({
  sock: socket,
  host,
  username: "acme",
  privateKey: process.env.SFTP_PRIVATE_KEY,
});
await sftp.put("./settlement.csv", "/inbound/settlement.csv");
await sftp.end();

Sources

Checked October 2026. Confirm current details on the vendor's site before you decide. Prices and limits change.

Frequently asked questions

How do I connect to an IP-allowlisted SFTP server from AWS Lambda?

Open the TCP connection through a SOCKS5 proxy with a static IP and pass that socket to your SFTP library, such as ssh2-sftp-client or paramiko. Then ask the partner to allow the proxy's IPs.

Does host key verification still work through a proxy?

Yes. SSH runs end to end between your client and the server, so the server presents its real host key. With a local tunnel, set HostKeyAlias to the real hostname so the check matches.

Can the proxy see my files?

No. The proxy forwards SSH's encrypted bytes. It logs the destination, bytes, and result of each connection, not file names or contents.

Does this work for FTP or FTPS?

Only with a client that sends both the control and data connections through SOCKS5. SFTP uses one connection, which makes it much simpler to route through a static IP.

Make it fixed.

Fixedmark is in early access. Join the list to get dedicated static IPs when your region opens.