Skip to main content
ElevenLabs Documentation Docs

Search documentation

Type to search this documentation.

On this pageOverview

IP allowlisting

If your infrastructure requires IP-based access controls, you can add ElevenLabs' static egress IP addresses to your firewall allowlist. All outbound requests from ElevenLabs services—including webhooks, WebSocket connections, and MCP server requests—originate from these addresses.

The following IP addresses are used for all ElevenLabs services:

Region IP Address
US (Default) 34.67.146.145
US (Default) 34.59.11.47
EU 35.204.38.71
EU 34.147.113.54
Asia 35.185.187.110
Asia 35.247.157.189

If you are using a data residency region, outbound requests use the following IPs:

Region IP Address
EU Residency 34.77.234.246
EU Residency 34.140.184.144
India Residency 34.93.26.174
India Residency 34.93.252.69
Singapore Residency 34.87.23.17
Singapore Residency 34.126.179.103

IP allowlisting is useful when:

  • Your webhook endpoints are behind a firewall that restricts inbound traffic
  • Your Speech Engine server only accepts connections from known sources
  • Your MCP server integration requires IP-based access controls
  • Your SIP trunk provider requires IP allowlisting for authentication

The static egress IPs apply to all outbound requests from ElevenLabs, including:

  • Post-call webhooks: Notifications sent after ElevenAgents calls complete. See post-call webhooks.
  • Speech Engine: WebSocket connections from ElevenLabs to your server. See Speech Engine.
  • MCP server requests: Requests to your Model Context Protocol servers. See MCP security.
  • Webhook tools: Outbound calls from agent webhook tools.

For webhook endpoints, use IP allowlisting together with HMAC signature validation to verify that requests originate from ElevenLabs.

For Speech Engine servers, IP allowlisting can replace or supplement JWT verification. If your server sits behind infrastructure that restricts traffic to ElevenLabs' egress IPs, you can disable JWT verification by setting disableAuth: true (TypeScript) or disable_auth=True (Python). See the JavaScript SDK reference or Python SDK reference for details.

You can also restrict your ElevenLabs API keys to only work from specific IP addresses. This is a separate feature from egress IP allowlisting and controls which IPs can make requests to the ElevenLabs API.

See API key IP allowlisting for details.

Suggest an edit

Propose a replacement for this page. The site team reviews it before applying any changes.

Export
Documentation menu