Skip to content

URL Whitelist

Below is the list of domains/URLs that need to be whitelisted in your firewall for Fleet to work properly from a browser.

These are essential — Fleet will not function without them.

DomainPortReason
fleet.binalyze.ai443The Fleet application (UI, API, auth)
*.binalyze.ai443Sandbox API (agent sessions, files, workspace)
*.binalyze.ai443Sandbox WebSocket (in-browser terminal, over WSS)
*.r2.cloudflarestorage.com443File attachment uploads via presigned URLs
*.onkernel.com8443Browser live-view (remote desktop stream)

Plus at least one OAuth provider set, depending on which login method you use:

DomainPortReason
accounts.google.com443Google sign-in consent screen
oauth2.googleapis.com443Google OAuth token exchange
DomainPortReason
login.microsoftonline.com443Microsoft sign-in consent screen
DomainPortReason
www.linkedin.com443LinkedIn sign-in consent screen
api.linkedin.com443LinkedIn OAuth token/profile exchange

Fleet works without these. The impact of blocking each one is noted.

DomainPortImpact If Blocked
*.sentry.io443Error reporting stops (no user-facing impact)
lh3.googleusercontent.com443Google profile avatars won’t load (placeholder shown)
media.licdn.com443LinkedIn profile avatars won’t load (placeholder shown)
kb.binalyze.ai443”Knowledge Base” sidebar link won’t open (new tab only)
Binalyze corporate website443”Contact Support” link won’t open (new tab only)
cdn.skypack.dev443Sandbox landing page animation won’t load (cosmetic only)