Skip to main content

Retool IP addresses

Cloud instances must ensure that any configured resources, such as APIs and databases, allow access from Retool's IP addresses. If you make use of inbound firewall rules, include the following IP addresses in its allowlist. Refer to your data source or firewall documentation for specific guidance.

IP addresses​

By default, Retool uses the AWS us-west-2 region, based in Oregon, US. To route resources through Europe or other regions, see the outbound regions documentation.

To allow Retool access from one of its outbound regions, you must include the necessary IP addresses in your allowlist if you use inbound firewall rules. You can also use the Get IP Allowlist by Region endpoint to retrieve this list programmatically.

CIDR IP addresses
35.90.103.132/30
44.208.168.68/30
Individual IP addresses
35.90.103.132
35.90.103.133
35.90.103.134
35.90.103.135
44.208.168.68
44.208.168.69
44.208.168.70
44.208.168.71

If you self-host Retool, refer to the self-hosted network and storage requirements for additional details.

Configure rules for app builder​

If your organization makes use of firewall rules, you must include retool.app in its allowlist. This allows your instance to connect to Retool's user authentication and usage reporting services.

This step is required because published apps are served at retool.app, using the following URL structure: <orgSubdomain>--<app-name-slug>.retool.app. For example, an example app URL could be exampleOrg--overtime-requests.retool.app.