n8n Static IP: HTTP Request Node Proxy Setup
n8n's HTTP Request node has a Proxy option. Paste your Fixedmark proxy URL there and that node's requests leave from your dedicated IP pair, on n8n Cloud or self-hosted. Partners allowlist two IPs that belong to you, not the shared addresses n8n Cloud publishes for every workspace.
Why n8n's outbound IP is not yours
n8n Cloud publishes the IP ranges its instances use, but per n8n's docs they are shared with other customers, no address is unique to your instance, and an instance's IP can change if n8n moves it to another cluster. Allowlisting them lets other n8n Cloud workspaces in too. Self-hosted n8n inherits the IP of wherever you run it, which changes on most PaaS platforms and on home or office connections.
Vendors that protect admin or payment APIs by IP (ERP systems, banks, some CRMs, internal tools behind a firewall) need a source address that is stable and specific to you.
n8n's native options
n8n does not sell dedicated outbound IPs. Self-hosting on a VM with a static IP works if you already run your own server. Otherwise the HTTP Request node's Proxy option routes specific calls through a fixed address. Per n8n's docs, the node's Proxy option takes precedence over the global HTTP_PROXY, HTTPS_PROXY, and ALL_PROXY variables, which self-hosted instances can set to route every HTTP call.
Current n8n releases tunnel through the proxy with https-proxy-agent, which supports https:// proxy URLs.
Sources for n8n pricing
Checked October 2026. Confirm current details on the vendor's site before you decide. Prices and limits change.
- n8n docs: HTTP Request node
- n8n docs: Find your n8n Cloud IP addresses
- n8n docs: v2.0 breaking changes
- n8n source: proxied agents
Set up a static IP on n8n
You set the proxy per HTTP Request node, so only the nodes that call allowlisted APIs use it.
Fixedmark is in early access. Proxy URLs are issued at launch. Join early access to get yours when your region opens.
Before you start
- An n8n Cloud workspace or a self-hosted n8n instance. Use a current release.
- A Fixedmark proxy URL (
https://APP_ID:TOKEN@mum.egress.fixedmark.com:443) and the two IPs of your pair. Both are issued at launch. Join early access to get them. - Access to the partner's or database's allowlist, or a contact who can add two IPv4 addresses for you.
Steps
- 1Open the HTTP Request nodeIn the node that calls the allowlisted API, open Options, choose Add option, and pick Proxy.
- 2Paste the proxy URLEnter the full Fixedmark URL, including the credentials. On self-hosted n8n you can use the expression
{{ $env.FIXEDMARK_PROXY_URL }}instead. n8n 2.0 and later block env access in expressions by default, so setN8N_BLOCK_ENV_ACCESS_IN_NODE=falsefirst. - 3Check the IPAdd the IP check node below with the same Proxy option and run it. The output should be one of your two Fixedmark IPs.
- 4Allowlist both IPs and run the workflowSend both addresses to the vendor, then run the real node.
{
"name": "Call partner API",
"type": "n8n-nodes-base.httpRequest",
"typeVersion": 4.2,
"parameters": {
"url": "https://api.partner.example/v1/orders",
"options": {
"proxy": "https://APP_ID:TOKEN@mum.egress.fixedmark.com:443"
}
}
}# docker compose .env for self-hosted n8n
# Option A: one variable that nodes read through an expression.
FIXEDMARK_PROXY_URL=https://APP_ID:TOKEN@mum.egress.fixedmark.com:443
# n8n 2.0+ blocks env access in expressions by default.
# Only allow it on instances where you trust every workflow editor.
N8N_BLOCK_ENV_ACCESS_IN_NODE=false
# Then set the node's Proxy option to: {{ $env.FIXEDMARK_PROXY_URL }}
# Option B: route every HTTP call from n8n through the proxy.
# HTTPS_PROXY=https://APP_ID:TOKEN@mum.egress.fixedmark.com:443
# NO_PROXY=localhost,127.0.0.1,postgres,redisBuilt-in app nodes (Slack, Google Sheets, and similar) do not expose a proxy option. On self-hosted n8n, the global HTTPS_PROXY variable covers them, along with every other outbound call. On n8n Cloud, call the vendor's API with an HTTP Request node instead.
Verify the egress IP on n8n
Check the IP before you send it to a partner. Paste the node below into a workflow (copy the JSON, then paste on the canvas) and run it. On self-hosted n8n you can also run curl from the container. The endpoint https://fixedmark.com/api/ip returns the caller's IP as plain text, and the What's my IP tool shows the same thing in a browser.
The proxied call should print one of your two Fixedmark IPs every time. The direct call should print a different address. If both print the same platform IP, the client is not using the proxy.
{
"name": "Check egress IP",
"type": "n8n-nodes-base.httpRequest",
"typeVersion": 4.2,
"parameters": {
"url": "https://fixedmark.com/api/ip",
"options": {
"proxy": "https://APP_ID:TOKEN@mum.egress.fixedmark.com:443"
}
}
}# Needs curl 7.52 or later for an https:// proxy URL.
# Prints the IP the destination sees. Run it a few times:
# you should only ever see the two IPs of your pair.
curl -sS --proxy "$FIXEDMARK_PROXY_URL" https://fixedmark.com/api/ip
# Same check over SOCKS5, the path database drivers use.
curl -sS --proxy "$FIXEDMARK_SOCKS_URL" https://fixedmark.com/api/ip
# Without the proxy, for comparison. This is the platform's own IP.
curl -sS https://fixedmark.com/api/ipDatabases from n8n
n8n's Postgres, MySQL, and MongoDB nodes have no proxy setting. On self-hosted n8n, run bm tunnel 5432:db.example.com:5432 (planned for launch) next to n8n and point the credential at 127.0.0.1. In Docker Compose, run the tunnel as its own service and point the credential at that service name. On n8n Cloud, use the database's HTTP API through an HTTP Request node, or expose a small API in front of the database. See Postgres and MySQL allowlists.
Common errors and fixes
access to env vars denied in the Proxy expression
n8n 2.0 and later block $env in expressions by default. Set N8N_BLOCK_ENV_ACCESS_IN_NODE=false on instances you control, or paste the URL directly.
Webhooks or internal calls break after setting global HTTPS_PROXY
The global variable also catches calls to your own services. Add them to NO_PROXY, for example NO_PROXY=localhost,127.0.0.1,postgres,redis.
407 Proxy Authentication Required
The proxy did not get valid credentials. Check that the env var holds the full URL with APP_ID:TOKEN@, with no quotes or trailing newline. If the token contains @, :, or /, URL-encode it. Some clients drop credentials from the URL: pass them separately (Deno's basicAuth, axios proxy.auth) or switch to undici's ProxyAgent, which reads them from the URL.
TLS errors to the proxy: wrong version number, EPROTO, Proxy CONNECT aborted, or unable to connect to proxy
The client does not support an https:// proxy URL and is speaking plain HTTP to port 443. Upgrade it: curl 7.52+, urllib3 1.26+ (requests), httpx 0.26+, undici ProxyAgent, Go 1.10+. In Ruby, use Typhoeus: Net::HTTP and Faraday's default adapter cannot tunnel HTTPS through a TLS proxy. For older axios releases, set proxy: false and pass https-proxy-agent as httpsAgent. Java's built-in HttpClient cannot speak TLS to a proxy at all. If you cannot upgrade, use the SOCKS5 URL.
ETIMEDOUT or ECONNRESET to the partner, or a 403 from the partner
The proxy connected, but the destination dropped you. Usually only one IP of the pair is on the allowlist, or the partner has not applied the change yet. Add both IPs. If a destination allowlist is set on your Fixedmark token, check the host and port are on it.
The IP check prints the platform's IP, not a Fixedmark IP
The request went direct. Node's built-in fetch ignores HTTPS_PROXY unless NODE_USE_ENV_PROXY=1 is set (Node 22.21+ and 24+). Many SDKs ignore proxy env vars too. Pass the proxy to the client explicitly, as in the snippets above.
429 or 407 with an X-Proxy-Error: quota_exceeded header
Planned behavior when you pass your plan's soft limit. Check usage in the dashboard or raise the plan.
Database driver has no proxy option
node-postgres, mysql2, psycopg, and most ORMs cannot use an HTTP proxy. Use a SOCKS5-capable driver with FIXEDMARK_SOCKS_URL, or run bm tunnel where the platform allows a second process.
Gotchas on n8n
The proxy URL contains a credential. On n8n Cloud, anyone who can edit the workflow can read it. Use a destination allowlist on the token so it can reach only the vendor's host.
- n8n reads lowercase
https_proxybefore uppercaseHTTPS_PROXY. Set only one to avoid surprises.
Related guides
- Use caseAI agents and automationsGive n8n workflows, Lovable apps, and AI agent tool calls a fixed IP that allowlisted APIs accept.
- Use casePartner API allowlistingGive Salesforce, SOAP vendors, and payment gateways one dedicated IP pair to allowlist, wherever your code runs.
- IntegrationGitHub ActionsRoute deploy and sync steps through a fixed IP without self-hosted runners.
- IntegrationSupabase Edge FunctionsFixed outbound IPs for Supabase and Lovable Edge Functions with Deno's proxy client.
Frequently asked questions
How do I give n8n a static IP?
Add the Proxy option to the HTTP Request node and paste a static IP proxy URL. Requests from that node then leave from the proxy's fixed IPs.
Does n8n Cloud have a static IP?
n8n Cloud publishes the IP ranges it uses, but they are shared with other customers and can change if your instance moves clusters. For an IP only you use, set a static IP proxy on the HTTP Request node.
How do I set a proxy for all of self-hosted n8n?
Set HTTPS_PROXY (and NO_PROXY for internal hosts) in the n8n container's environment. A Proxy option on an individual node overrides it.
Do other n8n nodes use the proxy?
Only nodes where you set the Proxy option, unless you set the global HTTPS_PROXY variable on a self-hosted instance.
Fix your egress IP.
Fixedmark is in early access. Join the list to get a dedicated IP pair for n8n when your region opens.