Toast Firewall Allowlist

Last updated: Oct 22, 2025, 10:50 AM

In order to successfully install and operate the most up-to-date version of Toast, the domains listed in this article must be allowed in your router or firewall settings.

In this Article:

 

If you use allowlist domains in your firewall, you'll need to include the domains listed below.

A firewall allowlist is a list of domains that are configured on a firewall or router to be explicitly allowed to pass traffic without any restrictions. This does not apply to all customers, only to those who have already configured firewall settings to block/restrict specific domains.
 

U.S. and International Firewall Allowlist

Wildcarded domains (recommended):
 

Protocol
DestinationDestination Port
UDPAny53
UDPAny123
ICMP8.8.8.8/32Any
ICMP75.75.75.75/32Any
ICMP8.8.4.4/32Any
TCP162.159.153.239/32, 162.159.152.25/32443,8443,36868
TCP*.toasttab.com443,8443,36868,5671
TCP*.toasttab.com80,8080,8443
UDP*.toasttab.com3478
TCPd2c9w5yn32a2ju.cloudfront.net443
TCP*.launchdarkly.com443
TCPapi.mapbox.com443
TCPgoogle-analytics.com443
TCP*.googleapis.com443
TCPs3.amazonaws.com443
TCPs3-external-1.amazonaws.com443
TCPtoasttab.s3.amazonaws.com443
TCPtoast-perf-mon.s3.amazonaws.com443
TCPmg.adups.cn443
TCPfotadown.mayitek.com80
TCPhwfotadown.mayitek.com80
TCPoskm.mayitek.com80
TCPfota5.adups.cn443
TCPfruet.adups.com443
TCPosqn.mayitek.com80
TCP*.ingest.sentry.io443
TCP*.wootric.com443
TCP*.appcues.com443
TCPwootric-eligibility.herokuapp.com443
TCPd8myem934l1zi.cloudfront.net443
TCPmanage.eloview.com443
TCPapi.sunmi.com443
TCPota.cdn.sunmi.com443
TCPtms.bbpos.com443,63357
TCP*.toasttab.auth0.com80,443,4443,53
TCPfw-update.ubnt.com443
TCPfw-download.ubnt.com443
TCPdl.ui.com443
TCP*.sunmi.com443,80
TCPapk.cdn.sunmi.com.wsdvs.com443
TCPota.cdn.sunmi.com.mgslb.com443
TCPapk.cdn.sunmi.com.w.kunlunar.com443
TCPota.cdn.sunmi.com.w.kunlunar.com443
TCPfile.cdn.sunmi.com.w.kunlunar.com443
TCPpic.cdn.sunmi.com.w.kunlunar.com443
TCPd10br2b8k9bn0s.cloudfront.net443
TCPmaven.n.miliao.com8081
TCPjivesoftware.com443
TCPnexus.d.xiaomi.net443
TCPpic1.ooopic.com443
TCP*.1e100.net80,443
TCPbit.ly443
TCPpendo-static-5740812351307776.storage.googleapis.com443
TCP*.pendo.io443
TCPcdn.jsdelivr.net443
TCPunpkg.com443
TCPhttp-inputs-toast.splunkcloud.com443
TCPapp-ab35.marketo.com443
TCPio.eloview.com443
TCPcontent.eloview.com443
TCPdevice.eloview.com443
TCPdsq.eloview.com443
TCPcdn2.hubspot.net443
TCPcdn.auth0.com443
TCPd2w1ef2ao9g8r9.cloudfront.net443
TCPbrowser.sentry-cdn.com443
TCPssl.google-analytics.com443
TCPapis.google.com443
TCPplus.l.google.com443
TCP*.gstatic.com443
TCPd1pxgl8l8levq9.cloudfront.net443
TCPsentry.io443
TCPmaxcdn.bootstrapcdn.com443
TCPservice.force.com443
TCP*.salesforceliveagent.com443
TCPcdn.ravenjs.com443
TCP*.glance.net443,5500,5501
TCP*.ecardsystems.com443
TCPcaptive.apple.com443,80
TCP*.eloview.com443
UDP2.android.pool.ntp.org123
TCPapi.memfault.com443
TCPfiles.memfault.com443
TCPdevice.memfault.com443
TCPingress.memfault.com443
TCPchunks.memfault.com443
TCPmemfault-prod-east1.s3.amazonaws.com443
TCPfota5.adups.com443
TCPsdk.iad-05.braze.com443
TCPrecaptcha.net443
TCPappboy-images.com443
TCPbraze-images.com443
TCPcdn.braze.eu443
TCPmemfault.com443
TCPosqn.mayitek.com 443
TCP23.22.57.16/32443
TCP44.209.216.48/32443
TCP52.7.18.112/32443
TCP34.228.97.229/32443
TCP54.173.90.154/32443
TCPtoast-cc-config-update-prod.s3.amazonaws.com443
TCP*.okta.com443
TCP*.mtls.okta.com443
TCP*.oktapreview.com443
TCP*.mtls.oktapreview.com443
TCP*.oktacdn.com443
TCP*.okta-emea.com443
TCP*.mtls.okta-emea.com443
TCP*.kerberos.okta.com443
TCP*.kerberos.okta-emea.com443
TCP*.kerberos.oktapreview.com443
TCP*.okta-gov.com443
TCP*.mtls.okta-gov.com443
TCP*.okta.mil443
TCP*.mtls.okta.mil443
TCP3.145.240.0/25443
TCP52.32.63.128/26443
TCP54.236.251.192/26443
TCP54.241.191.128/26443
UDPnetwork-device-syslog.prod.toasttabdns.com5140
UDPnetwork-device-syslog.prod.toasttabdns.com5142
TCPvault.joinforage.app443
TCPapi.joinforage.app443
TCPtntbcrncmgi.live.verygoodproxy.com443
ICMPv4*.adyen.comAny
TCP*.adyenpayments.com443
TCP*.adyen.com443