> ## Documentation Index
> Fetch the complete documentation index at: https://pipedream.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Network Access

> Every host Conduit connects to, when it connects, and how outbound requests are hardened.

Conduit needs no inbound access beyond the port it listens on. This page is the
outbound picture — what to allow if egress from the Conduit container is
filtered, and what each host is actually used for.

A Conduit instance with no connectors, no email provider, and no IAM database
authentication configured makes no outbound requests at all. There is no phone-home, license check, or update poll.
(What the image *build* downloads is separate and also enumerated — see
[Build from Source](/docs/conduit/deploy/build-from-source).)

## Fixed hosts

These are the only hostnames compiled into Conduit. Each is contacted **only**
when the feature next to it is in use, so an instance that doesn't use the
feature never resolves the host.

| Host | Used for | Contacted when |
| - | - | - |
| `api.pipedream.com` | Minting the workspace's Pipedream OAuth token (`/v1/oauth/token`), reading and revoking a user's connected accounts and issuing Connect tokens (`/v1/connect/…`), and the app catalog that populates the connector picker (`/graphql`) | A workspace has the Pipedream connector configured and connected |
| `remote.mcp.pipedream.net` | Listing and calling Pipedream tools — the Pipedream MCP endpoint | Same as above. Overridable per workspace, so a self-hosted Pipedream MCP endpoint replaces this host |
| `api.resend.com` | Sending invitation and notification email | The email provider is set to Resend |
| `email.<region>.amazonaws.com` | Sending invitation and notification email | The email provider is set to Amazon SES. The region comes from the SES configuration, so allow the one region you configured |
| `sts.<region>.amazonaws.com` | Exchanging the instance's Kubernetes service-account token for the AWS credentials that sign database auth tokens | `CONDUIT_DATABASE_AUTH=rds-iam` is set and credentials come from an EKS service-account role (IRSA). Instance-profile and Pod Identity credentials come from node-local metadata endpoints instead, which no egress filter sees |

## Hosts you configure

There is no fixed list for these — they are whatever an administrator enters,
and each is contacted only by the feature that owns it:

* **Identity providers** — issuer discovery, token, and JWKS endpoints for each
  identity provider you add, contacted during sign-in.
* **Upstream MCP servers** — every connector of type URL or SSE, contacted on
  `tools/list` and `tools/call`. Conduit's built-in catalog offers
  `mcp.linear.app`, `mcp.supabase.com`, and `mcp.atlassian.com` as one-click
  suggestions; they are contacted only once an administrator actually adds one.
* **OpenAPI and GraphQL connectors** — the API base URL you configure, plus the
  spec or schema URL if you point at one rather than pasting it.
* **SMTP server** — your mail host, when the email provider is SMTP. This is a
  direct SMTP connection, not HTTP, and is not subject to the hardening below.
* **Instance telemetry exporters** — the OTLP collectors instance
  administrators configure in Settings → Instance → Telemetry, or via the
  standard `OTEL_EXPORTER_OTLP_*` variables. Deliberately exempt from the
  hardening below, because a collector normally *is* on a private in-cluster
  address.
* **Workspace telemetry exporters** — the `https` OTLP endpoints workspace
  administrators configure in their workspace's Settings → Telemetry. These
  are tenant-supplied, so they are **not** exempt: they go through the
  hardened client like connectors, and a hostname that resolves to a private
  address is refused unless listed in `CONDUIT_SAFEHTTP_ALLOWED_PRIVATE_HOSTS`.
  See [Telemetry Export](/docs/conduit/configure/telemetry).
* **OAuth client metadata documents** — an `https` URL supplied by a connecting
  MCP client, fetched when it asks to authorize so Conduit can identify it.
  The host is the client vendor's own, so it is not a fixed host; which
  clients may then connect is decided per workspace under Settings → MCP
  Clients (see
  [Governing connected clients](/docs/conduit/use/mcp-authorization#governing-connected-clients)).

## Hosts the browser reaches

These are loaded by the browser of someone using the web UI, not by the Conduit
container, so they belong in a user-network policy rather than a container
egress rule:

* `pipedream.com` — the connect-account flow runs in an iframe from this origin.
* Connector icons — `www.google.com/s2/favicons` and `assets.pipedream.net` for
  catalog entries, plus any `https` URL an administrator sets as a connector's
  icon. The Content-Security-Policy allows images from any `https` origin for
  this reason; every other directive is pinned.
* `pipedream.com/docs/conduit` — only if `/docs/` is configured to redirect to the
  public documentation site instead of serving the copy embedded in the image.
  The embedded copy loads nothing from outside the instance.

## How outbound requests are hardened

Every HTTP request Conduit makes — to a fixed host above or one you configured —
goes through a single hardened client. It refuses to connect to private,
loopback, link-local, and other special-use addresses, checked **after DNS
resolution** so a hostname that resolves to an internal address is caught too.
For a well-known NAT64 (`64:ff9b::/96`) or 6to4 (`2002::/16`) address, Conduit
checks the IPv4 address it carries. Local-use NAT64, IPv4-compatible,
IPv4-translated and Teredo addresses are blocked whatever IPv4 address they
carry.
It never follows redirects, and it requires `https`. Response sizes are capped,
and a reply over the cap is refused rather than truncated.

Two settings adjust this, and both are exceptions rather than modes:

* `CONDUIT_SAFEHTTP_ALLOWED_PRIVATE_HOSTS` lists exact hostnames that may
  resolve to a private address — see
  [Private endpoints and gateways](#private-endpoints-and-gateways) below for
  the rules and worked examples. `https` is still required.
* `CONDUIT_SAFEHTTP_ALLOW_LOCALHOST` is for development only: it permits plain
  `http` to loopback, so a local identity provider or upstream on
  `http://localhost:PORT` is reachable. Never enable it in production.

Three exemptions bypass this client: the SMTP connection, the OTLP collector
(both noted above), and the AWS credential lookups made when
`CONDUIT_DATABASE_AUTH=rds-iam` is set — those go through the AWS SDK, whose
endpoints are fixed AWS infrastructure rather than configurable URLs. The
database connection itself is PostgreSQL wire protocol, not HTTP, like the
SMTP case.

## Private endpoints and gateways

Sometimes a host you trust resolves to a private address *on purpose*: a
vendor's API consumed through a private endpoint or gateway (e.g. AWS
PrivateLink), a service behind an enterprise egress proxy, or an MCP server on
your own network — including one deployed into an isolated VPC or private
subnet that only Conduit can reach. The hardened client cannot tell that from
an SSRF attempt, so the request is refused with an error like:

```
blocked: connection to special-use address 10.91.37.177
```

`CONDUIT_SAFEHTTP_ALLOWED_PRIVATE_HOSTS` lifts the block for hosts you name: a
comma-separated list of exact hostnames that are allowed to resolve to private
addresses.

* **Hostnames only.** No URLs, ports, IP addresses, CIDR ranges, or wildcards —
  an invalid entry refuses to boot rather than silently weakening the
  protection. Matching is exact, so list every hostname; subdomains are not
  covered.
* **`https` is still required**, and the certificate must be valid for the
  hostname. A private endpoint that preserves the service's public DNS name (as
  PrivateLink does) satisfies this as-is.
* **Read at boot.** Set it in the container's environment and restart —
  re-saving the connector is not enough.

### Example: Pipedream through a private endpoint

The Pipedream connector reaches two hosts (see [Fixed hosts](#fixed-hosts)):
`api.pipedream.com` and `remote.mcp.pipedream.net`. If they resolve to private
addresses in your network, allow both:

```sh theme={null}
docker run -d --name conduit \
  -p 7272:7272 \
  -v conduit-data:/data \
  -e CONDUIT_BASE_URL=https://conduit.example.com \
  -e CONDUIT_SAFEHTTP_ALLOWED_PRIVATE_HOSTS=api.pipedream.com,remote.mcp.pipedream.net \
  ghcr.io/pipedreamhq/conduit:stable
```

If a workspace overrides the Pipedream MCP server URL, list that URL's hostname
in place of `remote.mcp.pipedream.net`.

### Example: an MCP server on your own network

List the hostname from the connector's URL — for a connector pointing at
`https://mcp.internal.example.com/mcp`:

```sh theme={null}
CONDUIT_SAFEHTTP_ALLOWED_PRIVATE_HOSTS=mcp.internal.example.com
```

On Kubernetes the variable goes through the Helm chart's `extraEnv` (see
[Kubernetes](/docs/conduit/deploy/kubernetes)):

```yaml theme={null}
extraEnv:
  - name: CONDUIT_SAFEHTTP_ALLOWED_PRIVATE_HOSTS
    value: mcp.internal.example.com
```

The same recipe covers every other host you configure that lives on a private
network — an on-premises identity provider, an internal OpenAPI or GraphQL
endpoint.
