Skip to content
Fixedmark
Integration · PaaS and containers

Railway Static IP: Dedicated Outbound IP Pair

Railway includes Static Outbound IPs on the Pro plan, but Railway's docs say the IPs may be shared with other customers and change if you move regions. When a partner needs an address that belongs only to you, route those calls through a Fixedmark proxy URL and allowlist your dedicated pair.

Why Railway's outbound IP changes

Railway schedules your service onto shared hosts in a region. By default, outbound connections leave from whichever host the deployment lands on, so a redeploy, a restart, or a scaling event can change the source address. Nothing in your code controls it.

Partners that allowlist by IP see a new address and drop the connection. The usual symptoms are a 403 from a payment or bank API, a timeout to MongoDB Atlas, or a no pg_hba.conf entry error from Postgres right after a deploy.

Railway Static Outbound IPs: what you get

Railway's Static Outbound IPs feature is available on the Pro plan, which costs $20 per workspace per month with $20 of usage included. Railway's docs and pricing page list no separate fee for it. Per the docs, the IPs are IPv4 only, may be shared with other Railway customers, change if you move the service to another region, and cannot receive inbound traffic.

For many allowlists that is enough. Choose a dedicated pair when the destination requires an address attributable to you alone (broker APIs under SEBI rules, some bank APIs), when you want the same IPs across Railway and other platforms, or when you need to switch regions without re-allowlisting.

Sources for Railway pricing

Checked October 2026. Confirm current details on the vendor's site before you decide. Prices and limits change.

Set up a static IP on Railway

Railway services are long-running containers, so you can use the HTTPS proxy for API calls and SOCKS5 or bm tunnel for databases in the same service.

Fixedmark is in early access. Proxy URLs are issued at launch. Join early access to get yours when your region opens.

Before you start

  • A Railway service on any plan. The proxy does not need Railway Pro.
  • A Fixedmark proxy URL (https://APP_ID:TOKEN@mum.egress.fixedmark.com:443) and the two IPs of your pair. Both are issued at launch. Join early access to get them.
  • For databases: the SOCKS5 URL (socks5h://APP_ID:TOKEN@mum.egress.fixedmark.com:1080) or the bm tunnel CLI.
  • Access to the partner's or database's allowlist, or a contact who can add two IPv4 addresses for you.

Steps

  1. 1
    Add the proxy URL as a service variableOpen the service, go to Variables, and add FIXEDMARK_PROXY_URL. For several services, add it once as a shared variable and reference it in each service with ${{ shared.FIXEDMARK_PROXY_URL }}.
  2. 2
    Add the SOCKS5 URL if you connect to a databaseAdd FIXEDMARK_SOCKS_URL the same way. Drivers with SOCKS5 support use it directly.
  3. 3
    Configure the HTTP clientPass the proxy URL to the client that calls the allowlisted API. Use the snippet for your runtime below. Leave other traffic direct.
  4. 4
    Deploy and verify the egress IPVariable changes trigger a redeploy. Run the IP check below. It should print one of your two Fixedmark IPs on every run.
  5. 5
    Allowlist both IPsGive the partner both addresses. Traffic is load-balanced across the pair, so allowlisting one causes intermittent failures.
// npm install undici  (undici 8 needs Node.js 22.19+)
import { fetch, ProxyAgent } from "undici";

// FIXEDMARK_PROXY_URL=https://APP_ID:TOKEN@mum.egress.fixedmark.com:443
const proxy = new ProxyAgent(process.env.FIXEDMARK_PROXY_URL);

const res = await fetch("https://api.partner.example/v1/orders", {
  dispatcher: proxy,
  headers: { authorization: `Bearer ${process.env.PARTNER_API_KEY}` },
});
console.log(res.status, await res.json());

SDKs that do not use fetch (the Stripe and Salesforce Node SDKs, got, axios) accept an HTTP agent. Pass new HttpsProxyAgent(process.env.FIXEDMARK_PROXY_URL) from the https-proxy-agent package, which supports https:// proxy URLs. With axios, also set proxy: false so it does not apply its own proxy logic. undici 8 needs Node 22.19 or later. On older Node, install undici@7.

Verify the egress IP on Railway

Check the IP before you send it to a partner. railway run runs a command locally with the service's variables, which tests the credentials. To test the deployed service, run the check from the service itself, for example as a one-off script in the start command. The endpoint https://fixedmark.com/api/ip returns the caller's IP as plain text, and the What's my IP tool shows the same thing in a browser.

The proxied call should print one of your two Fixedmark IPs every time. The direct call should print a different address. If both print the same platform IP, the client is not using the proxy.

# Needs curl 7.52 or later for an https:// proxy URL.
# Prints the IP the destination sees. Run it a few times:
# you should only ever see the two IPs of your pair.
curl -sS --proxy "$FIXEDMARK_PROXY_URL" https://fixedmark.com/api/ip

# Same check over SOCKS5, the path database drivers use.
curl -sS --proxy "$FIXEDMARK_SOCKS_URL" https://fixedmark.com/api/ip

# Without the proxy, for comparison. This is the platform's own IP.
curl -sS https://fixedmark.com/api/ip

Databases: Postgres, MySQL, and MongoDB

Database drivers do not speak HTTP CONNECT, so the proxy URL above does not cover them. On Railway you have two options. Drivers with SOCKS5 support can use FIXEDMARK_SOCKS_URL directly: the MongoDB Node.js driver accepts proxyHost and proxyPort options, and Go's pgx accepts a SOCKS5 dialer. For any other driver, run the bm tunnel CLI (planned for launch) as part of the start command, for example bm tunnel 5432:db.example.com:5432 & node server.js, then point the driver at 127.0.0.1.

TLS to the database stays end to end. Fixedmark forwards encrypted bytes and never sees your queries. If your driver verifies the server certificate, keep the real database hostname as the TLS server name when you connect through the local tunnel.

# Forward local port 5432 to the database through your Fixedmark IPs.
# bm tunnel is planned for launch; flags are not final.
bm tunnel 5432:db.example.com:5432 &

# Point the driver at the local end of the tunnel.
DATABASE_URL="postgres://app:secret@127.0.0.1:5432/app?sslmode=require"

Common errors and fixes

Calls to other Railway services fail after setting HTTPS_PROXY

A global proxy also catches *.railway.internal traffic. Remove the global variable and pass FIXEDMARK_PROXY_URL to specific clients, or add NO_PROXY=.railway.internal.

407 Proxy Authentication Required

The proxy did not get valid credentials. Check that the env var holds the full URL with APP_ID:TOKEN@, with no quotes or trailing newline. If the token contains @, :, or /, URL-encode it. Some clients drop credentials from the URL: pass them separately (Deno's basicAuth, axios proxy.auth) or switch to undici's ProxyAgent, which reads them from the URL.

TLS errors to the proxy: wrong version number, EPROTO, Proxy CONNECT aborted, or unable to connect to proxy

The client does not support an https:// proxy URL and is speaking plain HTTP to port 443. Upgrade it: curl 7.52+, urllib3 1.26+ (requests), httpx 0.26+, undici ProxyAgent, Go 1.10+. In Ruby, use Typhoeus: Net::HTTP and Faraday's default adapter cannot tunnel HTTPS through a TLS proxy. For older axios releases, set proxy: false and pass https-proxy-agent as httpsAgent. Java's built-in HttpClient cannot speak TLS to a proxy at all. If you cannot upgrade, use the SOCKS5 URL.

ETIMEDOUT or ECONNRESET to the partner, or a 403 from the partner

The proxy connected, but the destination dropped you. Usually only one IP of the pair is on the allowlist, or the partner has not applied the change yet. Add both IPs. If a destination allowlist is set on your Fixedmark token, check the host and port are on it.

The IP check prints the platform's IP, not a Fixedmark IP

The request went direct. Node's built-in fetch ignores HTTPS_PROXY unless NODE_USE_ENV_PROXY=1 is set (Node 22.21+ and 24+). Many SDKs ignore proxy env vars too. Pass the proxy to the client explicitly, as in the snippets above.

429 or 407 with an X-Proxy-Error: quota_exceeded header

Planned behavior when you pass your plan's soft limit. Check usage in the dashboard or raise the plan.

Database driver has no proxy option

node-postgres, mysql2, psycopg, and most ORMs cannot use an HTTP proxy. Use a SOCKS5-capable driver with FIXEDMARK_SOCKS_URL, or run bm tunnel where the platform allows a second process.

Gotchas on Railway

Railway's private networking between your own services is unaffected. Only traffic you send through the proxy uses the Fixedmark IPs.

  • Do not set HTTPS_PROXY globally if your service also calls Railway-internal hostnames. Pass the URL to specific clients instead.
  • If you also enable Railway's Static Outbound IPs, the proxy still decides what the partner sees. Calls through the proxy show the Fixedmark pair.
  • Inbound static IPs are on the Fixedmark roadmap, not in the launch release.

Frequently asked questions

Does Railway have static IPs?

Yes. Railway's Static Outbound IPs feature is available on the Pro plan. Railway's docs say the IPs are IPv4 only, may be shared with other customers, and change if the service moves to a different region.

Can I get a static IP on Railway's Hobby plan?

Railway's native static IPs need Pro. On Hobby, route the calls that need a fixed address through a static IP proxy URL stored as a service variable.

When is Railway's built-in static IP not enough?

When the destination requires an IP that only you use, when you run the same integration on several platforms, or when you need to move regions without asking the partner to update the allowlist.

Can I connect to an IP-restricted Postgres database from Railway?

Yes. Use a driver that supports SOCKS5, or run the bm tunnel CLI in your start command and connect to 127.0.0.1. TLS to the database stays end to end.

Does the proxy slow down my Railway service?

It adds one hop. If the Fixedmark region matches your Railway region, that is usually a few milliseconds per new connection. Reuse connections to avoid paying it per request.

Fix your egress IP.

Fixedmark is in early access. Join the list to get a dedicated IP pair for Railway when your region opens.