Repository navigation
docs: add Network Allowlist page (enterprise firewall/proxy domains) - #531
Conversation
New page (Home > Developer Tools) consolidating the CometChat domains an enterprise must allow so chat, calling, media and the dashboard work — so teams don't have to hunt them across the docs. - Recommended two-domain wildcard (*.cometchat.io, *.cometchat.com) + a per-domain breakdown by purpose (runtime chat/calls, media, dashboard/tooling, push, build/CI). - Domain-based guidance (IPs are dynamic; fixed ranges via CometChat on request). - WebRTC media / realtime WebSocket caveats stated honestly (not invented). - Wired into docs.json nav; cross-linked from rest-api/chat-apis Data Center Hosting. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01PT9pMg3MSZEW3gsb6jPc3E
|
Preview deployment for your docs. Learn more about Mintlify Previews.
💡 Tip: Enable Automations to automatically generate PRs for you. |
…000) + link Calls Network Requirements Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01PT9pMg3MSZEW3gsb6jPc3E
…tative whitelist Adds the real per-region hosts (ws-/rtc-/rtc-web-/apiclient-/websocket-/metrics-), the widget (widget-js) and dashboard (app.cometchat.com/.io), and the full port set (TCP 80/443/5222/7443, UDP 10000-20000). Removes hosts that weren't real (call-/calls./ assets.). Wildcard recommendation unchanged (it already covered all of these). Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01PT9pMg3MSZEW3gsb6jPc3E
…rset of help-center + docs) Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01PT9pMg3MSZEW3gsb6jPc3E
…n list Adds the cc-cluster-2.io and cc-edge-2.io runtime families (not just cometchat.io), and the previously-missing services: AI Agent Service, Moderation (rule-), Extensions, media-/files- uploads, CDN, Metrics, Visual Chat Builder, apimgmt, preview. Wildcard shortcut now lists all four families + apex domains, with a subdomain-depth caveat. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01PT9pMg3MSZEW3gsb6jPc3E
It was in the hidden Developer Tools tab (only shown after opening agent-skills/cli), so enterprises couldn't find it. Moved to Chat & Messaging > Fundamentals > Security, next to End-to-End Encryption — visible in the sidebar. No file move / URL change (stays /docs/network-allowlist); the REST 'Data Center Hosting' cross-link is unchanged. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01PT9pMg3MSZEW3gsb6jPc3E
…ion; fix duplicated Platform groups - Move Network Allowlist to a top-level Platform page right after Key Concepts (was buried under Platform > Features > Extensions > Security). URL unchanged (/docs/network-allowlist). - chat-apis: promote the inline note to a dedicated '## Network allowlist' section below Data Center Hosting. - Fix pre-existing nav duplication: the Platform tab listed 'User-Roles' and 'Guides' twice (a duplicated block after 'Media'); removed the duplicates so each shows once. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01PT9pMg3MSZEW3gsb6jPc3E
Browsers (JS SDK, Widget, web UI Kits) need TCP 443 only; native iOS/Android add 5222 and 7443; REST API is 443; calling media is UDP 10000–20000 with TCP 443 fallback. Say that browsers can't use or test 5222/7443, reword the warning that said realtime needs more than 443, and link the JS troubleshooting "WebSocket fails" row to the Ports section. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01NgVCxHs3h8m72GXvC8HaV1
|
Updated for ENG-39686, as Ketan asked on the ticket (it replaces the closed #546). Ports is now split by client type (
Other changes on the page:
Troubleshooting: the "WebSocket fails" row in Checks: This adds a commit after the existing approval, so it needs a quick re-review. |
|
Re-reviewed after Two content issues are still open, so I'm not approving yet. Should fix before merge
Nits
|
- Webhooks are the one inbound exception: new "Webhooks (inbound)" section; intro and Notes no longer say no inbound traffic at all. - Per-host list: add apimgmt/campaigns on all three families, api.cometchat.com, app-beta.cometchat.com and widget-js.cometchat.io. Extensions corrected to <extension>-<region>.<family> on all three families (the SDK builds https://<extension>-<region>.<domain>/, no App ID). "Every individual host" softened: only the wildcards are guaranteed complete. - Ports: React Native, Ionic and Flutter SDKs (and their UI Kits) sit in the WebSocket/443 row. Their SDKs use WSS on the chatWSSPort app setting, the same as the JS SDK, and never 5222/7443. - Nits: "same services as above", two labels (not three), & → &. - Merge main (70 commits behind). Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01NgVCxHs3h8m72GXvC8HaV1
|
Thanks for the re-review. Everything below is in 1. Inbound claim: fixed. A new Webhooks (inbound) section says CometChat POSTs to your webhook URL, so that server must accept inbound HTTPS. Source IPs aren't published, so the section recommends the webhook's Basic Auth. The intro (L11) and Notes (L195) now point there instead of saying there's no inbound traffic. 2. Per-host list: fixed, with two corrections.
Nits: all fixed.
React Native, Flutter and Ionic: they go in the 443 row, not the native row. Their SDKs are WebSocket-based: the RN and Ionic packages are pure JS, and Flutter v5 is pure Dart using Help Center article: not in this repo. It needs someone with Help Center access to apply the same split and drop TCP 80. Suggested text:
Needs a maintainer to confirm. I didn't change these, but DNS doesn't back them for our dev app (
These may be provisioned per app or per feature, so they need confirming against infra before the page claims them. Checks: |
Hosts end users' devices fetch at runtime, each checked in the shipped packages and sample apps and confirmed live (HTTP 200): - assets.cc-cluster-2.io: React/Angular UI Kit sounds (/uikits/static/audio/) and the web sample apps' sampledata.json - assets.cometchat.io: mobile sample apps' sampledata.json and sample avatars - data-<region>.cometchat.io: sample avatars (web sample apps) - cdn.cometchat.io: JS Calls SDK virtual backgrounds - cdn.cometchat-staging.com: JS Calls SDK 5.x background-blur model/wasm files - fonts.googleapis.com / fonts.gstatic.com: Roboto for the call screen The wildcard section now says these three non-CometChat-domain hosts are needed in addition to the wildcards. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01NgVCxHs3h8m72GXvC8HaV1
|
Added in
Other changes:
|
|
Re-reviewed after
One thing left before I approve: the three rows flagged above for a maintainer. App ID hosts are wildcard DNS records: a made-up App ID resolves on
All three contradict L70, "Each of these runs on all three runtime families". Suggested fix: move AI Agent Service and CDN to Nits
|
- AI Agent Service and Moderation move to the cometchat.io-only list (Moderation host is rule-<region>.cometchat.io; the <appId>.rule- pattern never resolved) - CDN: only cdn.cometchat.io resolves - Metrics: add metrics-<region>.cc-cluster-2.io - Ports: Flutter SDK v4 (UI Kits v4/v5) wraps the native SDKs; only Flutter SDK v5 is 443-only Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01NgVCxHs3h8m72GXvC8HaV1
|
@ketanyekale thanks, all items from your 30 Sep review are addressed in d3dc052. Every host was checked against 8.8.8.8, and App ID patterns were tested with a made-up App ID because of the wildcard DNS.
The other rows still resolve for a made-up App ID on all three families: |
…st, move under fundamentals/ - Calling section: signalling <appId>.xmpp.rtcv5-<region>.cometchat.io and TURN turn.rtcv5-<region>.cometchat.io (TCP 443), found in a live Calls SDK 5.0.6 call; media servers are reached by IP over UDP, with TURN as the fallback - Ports: name the hosts for calling and for 5222/7443 (<appId>.ws-<region>, older native SDKs); current native SDKs use websocket-<region> on 443 - Wildcard warning covers three-label-deep hosts - Build/CI: add library.cometchat.io (iOS SPM) - Move the page to fundamentals/network-allowlist (Platform tab convention) Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01NgVCxHs3h8m72GXvC8HaV1
|
Addressed the latest review in P1.1: Calling hosts (new "Calling (voice and video)" section, plus the Ports row). I joined a real two-person call with
P1.2: Ports 5222/7443 and the "Legacy WebSockets" host.
So current native SDKs use 443 like everything else. 5222/7443 belong to
P2: page location. Moved to Also fixed:
The review text I received was cut off after the page-location nit, so if there were more P2 items, please re-post them. 🤖 Generated with Claude Code |
…c host purpose, CDN move, nits - 5222/7443: native iOS/Android SDK v2.x only (Android 2.4.x and earlier, iOS 2.4.2 and earlier, which use raw XMPP); v3.0+ use WSS on 443, so Flutter SDK v4 moves to the 443 row - rtc-<region>: call screen for the older calling built into the Chat SDKs - Background-blur files: cdn.cometchat.io after Calls SDK 5.0.6; staging host only for 5.0.6 and earlier - Nits: four-domains wording vs third-party hosts, family row labels, optional tooling hosts api-explorer.cometchat.com and mcp.cometchat.com Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01NgVCxHs3h8m72GXvC8HaV1
|
Addressed in
🤖 Generated with Claude Code |
…ly; drop the staging CDN The Calls SDK fix moving these files to production ships in the next release. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01NgVCxHs3h8m72GXvC8HaV1
|
Dropped 🤖 Generated with Claude Code |
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01NgVCxHs3h8m72GXvC8HaV1
|
Fixed: "three hosts" → "two hosts" (L38), and the intro's "a few third-party hosts" → "two third-party hosts" to match. Both are 🤖 Generated with Claude Code |
Adds a single Network Allowlist page so enterprise customers can let CometChat through a corporate firewall, proxy or VPN without hunting for domains across the docs. It also closes ENG-39686 (ports split by client type).
What
New page
fundamentals/network-allowlist.mdx, under Chat & Messaging → Platform:Domains: CometChat's own hosts are on four domains.
cometchat.io,cc-cluster-2.ioandcc-edge-2.iocarry the runtime, andcometchat.comcarries the Dashboard and website. The JavaScript Calls SDK also uses a few third-party hosts, which are listed separately.Quickest option: allow the four wildcards plus the apex domains, with a warning that some hosts are two or three labels deep, so the rules need "any depth".
Per-service host list for teams that can't use wildcards:
cometchat.ioonly,<extension>-<region>.<family>),<appId>.xmpp.rtcv5-<region>.cometchat.ioand TURN relayturn.rtcv5-<region>.cometchat.io, both on TCP 443. Media servers are reached by IP, with TURN as the fallback. Alsortc-<region>.cometchat.io, the call screen for the older calling built into the Chat SDKs,api-explorer.cometchat.comandmcp.cometchat.com.The page says only the wildcards are guaranteed to stay complete.
Ports, split by client type:
<appId>.websocket-<region>.cometchat.io)<appId>.ws-<region>.cometchat.ioWebhooks (inbound): the one inbound exception. Secure the endpoint with Basic Auth, since source IPs aren't published.
Also covered: push notifications (Google and Apple domains), build and CI hosts (including
library.cometchat.iofor iOS Swift Package Manager), and domain-not-IP guidance.Also changed
rest-api/chat-apis.mdx: links to the page from Data Center Hosting.sdk/javascript/troubleshooting.mdx: the "WebSocket fails" row links to the Ports section.docs.json: the nav entry. It also removes the duplicated User-Roles and Guides groups (fundamentals/user-roles-and-permissionsandfundamentals/user-authwere listed twice); both pages stay in the nav once.How the hosts were checked
cdn.cc-*,<appId>.ai-agent-service-*.cc-*and<appId>.rule-*.@cometchat/calls-sdk-javascript5.0.6. Its only WebSocket waswss://<appId>.xmpp.rtcv5-us.cometchat.io/xmpp-websocket, its ICE server wasturns:turn.rtcv5-us.cometchat.io:443, and media connected through a relay. Both hosts resolve for us, eu and in./v3.0/meapp settings returnCHAT_HOST_APP_SPECIFIC: <appId>.websocket-<region>.cometchat.ioandCHAT_WSS_PORT: 443.CometChatPro3.x andCometChatSDK4.x read the host and port from those settings and use a WebSocket library (Starscream). Android SDKs 3.0.0 through 5.0.7 depend only on OkHttp.smack-tcp).<appId>.ws-<region>.cometchat.iohas 5222 and 7443 open.apimgmt.cc-cluster-2.io,campaigns.cc-cluster-2.io,api.cometchat.com(legacy API) andapp-beta.cometchat.com, and loadswidget-js.cometchat.iofor Widget assets.https://<extension>-<region>.<domain>/, with no App ID.Safety
mint validateshows only the warningsmainalready has, and every link and anchor resolves.Note for the Calls team
The page lists
cdn.cometchat.ioonly for the background-blur model files. JavaScript Calls SDK 5.0.6 still loads them fromcdn.cometchat-staging.com, where they return 200, whilecdn.cometchat.ioreturns 403 for them today. The fix ships in the next Calls SDK release; until then, blur on 5.0.6 depends on the staging host, which the page intentionally doesn't list.🤖 Generated with Claude Code
https://claude.ai/code/session_01NgVCxHs3h8m72GXvC8HaV1