Domains we connect to

Forge apps declare every domain they can reach, and that declaration is enforced by the platform rather than by us. Nothing can quietly connect somewhere undeclared.

The categories below are what those domains are for. Your own approved egress domains are added to this list by you, and by nobody else.


#When this matters

  • Firewall and proxy configuration.

  • Security questionnaires asking for an egress list.

  • Understanding what a browser does when it renders a page with diagrams.


#The detail

Thing

What happens

Atlassian

Confluence itself, for storage, permissions and page content.

Capable services

The rendering service and app backend.

Your own approved domains

Only those an administrator has added.

Nothing else

Undeclared domains are blocked by the Forge platform.


#A few things that catch people out

  • The enforcement is Atlassian's, not ours. That is what makes the declaration meaningful.

  • A self-hosted renderer means adding your own renderer's domain to the approved list.

  • The exact current list is shown on the Marketplace listing, and on the permissions screen when you install or update the app. For your own domains, see Administration.



Ask us the awkward questions. They have answers.