Top

What are the trusted Whatfix domains to whitelist?

Prev Next

If your organization uses a firewall or proxy to restrict network access to specific websites, you must whitelist the following domains to access Whatfix Mirror and load the required Workflows, Assessments, and AI Roleplays. These domains enable Whatfix to communicate with your application and fetch the required content.

Also, if your organization has a Content Security Policy (CSP) in place to block external code insertions, it could prevent Whatfix from working on your app.

To prevent this from happening and to resolve CSP violation errors, the following domains must be added as an exception (Whitelisted) as part of the application's CSP headers. For more information, see Content Security Policy Reference.

CSP directives to whitelist for all data centers:

The following subdomains need to be whitelisted under all three CSP directives, that is, frame-src, connect-src , and script-src:

Note:

If you cannot whitelist the subdomains, use the following URL patterns to ensure that your app can communicate with Whatfix:

Non-EU data centers:

  • https://cdn.whatfix.com/prod/*

  • https://whatfix.com/service/*

EU data centers:

  • https://eucdn.whatfix.com/prod/*

  • https://eu.whatfix.com/service/*

Info:

  • Both https://whatfix.com and https://cdn.whatfix.com use port 443, which is the port for the HTTPS Protocol.

  • Depending on the deployment model, you need to whitelist only the necessary directives.

Info:

The following domains also need to be whitelisted if you have configured Google Analytics for your account:

  • https://www.google-analytics.com

  • https://analytics.google.com

Whitelist Google Analytics (GA) domains only if you have GA configured for your account.

Deployment Model

CSP Directives

Domain/value

Export (Content on the same server)

connect-src

*whatfix.com

style-src

unsafe-inline

img-src

data:

font-src

*.whatfix.com

media-src

*.whatfix.com

Export (Content fetched from a different domain server)

connect-src

*.whatfix.com

script-src

*.<domain>, <domain>

frame-src

style-src

unsafe-inline

img-src

data:

font-src

*.whatfix.com

media-src

*.whatfix.com

CDN

connect-src

*.whatfix.com

script-src

*.whatfix.com

frame-src

img-src

unsafe-inline

img-src

data:

font-src

*.whatfix.com

media-src

*.whatfix.com


If your organization has enabled Mirror Roleplay, whitelist the following domains.

For more information, see Mirror with Roleplay and Introduction to Mirror Roleplay.

Note:

Mindtickle and Daily.co domains are mandatory for Mirror Roleplay. The other domains support additional functionality such as fonts, analytics, and diagnostics.

Service

Domain

Mindtickle

https://*.mindtickle.com

Daily.co

https://prod-ks.pluot.blue

https://*.daily.co

*.wss.daily.co

Google Fonts

https://fonts.gstatic.com

https://fonts.googleapis.com

Mixpanel

https://cdn.mxpnl.com

https://api-js.mixpanel.com

Datadog

https://www.datadoghq-browser-agent.com

https://rum.browser-intake-us5-datadoghq.com
https://browser-intake-datadoghq.com

Note:

  • Your IT Admin can help whitelist the domains mentioned on this page.

  • If you are using any video or image links in your Whatfix Content, then you need to whitelist those domains as well. For example, if you embed a YouTube video in a Pop-up, you need to whitelist youtube.com.

When do domains need whitelisting?

Whatfix recommends whitelisting the domains as soon as you start creating content using Whatfix. This way, content authors will not have any issues previewing and testing the content.

IP addresses to whitelist

To ensure that Whatfix can access your organization's resources for crawling knowledge base content and integrations, you need to whitelist certain IP addresses. For a list of all the IP addresses you need to whitelist, see IP Ranges.

Note:

IP addresses are the same for all users.

Best Practices

Ensure that the policy is applied consistently across your network, including any proxy or VPN your learners use to access Mirror simulations.

Privacy Policy | Whatfix Glossary | Whatfix Platform Status
Copyright © 2024 WHATFIX TM. All rights reserved.