Static IP for AI Agents and n8n Automations
AI agents and automation tools call APIs from cloud infrastructure with changing IPs, so allowlisted APIs reject them. Route those calls through a Fixedmark proxy URL, using the n8n HTTP Request node's proxy option or a proxied HTTP client in your agent's tools, and the API sees one dedicated IP pair.
Why automations hit IP allowlists
Automation platforms and agent frameworks run on shared cloud infrastructure. n8n Cloud, Make, and hosted agent platforms send requests from address pools that you do not control and that change over time. When a workflow or agent calls an internal API, a customer's ERP, or a vendor that allowlists IPs, the request is dropped.
Self-hosted n8n or an agent on Railway or Render has the same issue in a smaller form: the container's IP changes when it redeploys or the platform moves it.
n8n, Make, and Lovable
In n8n, the HTTP Request node has a Proxy option under Options. Paste your Fixedmark proxy URL there, and only that node's requests go through your IPs. See the n8n guide for details.
If a no-code tool has no proxy field, put a small function between the tool and the API. The tool calls your function, and the function calls the allowlisted API through Fixedmark. Lovable apps run their backend logic in Supabase Edge Functions, which can use a proxy through Deno.createHttpClient, as shown in the Supabase guide.
AI agent tool calls
An agent's tools are ordinary HTTP calls made by your code. Give the tools that hit allowlisted systems their own proxied client, and leave model API calls on the direct path. That keeps proxy bandwidth low and makes the logs readable.
Agents choose their own requests, so limit what they can reach. A destination allowlist on the Fixedmark token, such as erp.customer.example:443, means a prompt-injected agent cannot use your static IP to reach other hosts. Connection logs record every destination the agent contacted.
Give an agent or workflow a static IP
Use the same proxy URL for every workflow and agent that needs the allowlisted IP.
Fixedmark is in early access. Proxy URLs are issued at launch. Join early access to get yours when your region opens.
- 1Create an endpointChoose the region closest to the API your workflows call.
- 2Allowlist both IPs at the destinationSend both addresses of your pair to the API owner or add them to the vendor's allowlist.
- 3Add the proxy URLIn n8n, set it on the HTTP Request node's Proxy option. In code, store it as
FIXEDMARK_PROXY_URL. - 4Proxy only the tools that need itCreate a proxied HTTP client for allowlisted tools. Keep model and public API calls direct.
- 5Restrict destinationsAdd a destination allowlist so the token can reach only the hosts your agent is meant to call.
HTTP Request node
Method: POST
URL: https://api.partner.example/v1/orders
Options
Add option > Proxy
Proxy: <your Fixedmark proxy URL from the dashboard>// npm install undici (undici 8 needs Node.js 22.19+)
import { fetch, ProxyAgent } from "undici";
// FIXEDMARK_PROXY_URL=https://APP_ID:TOKEN@mum.egress.fixedmark.com:443
const proxy = new ProxyAgent(process.env.FIXEDMARK_PROXY_URL);
const res = await fetch("https://api.partner.example/v1/orders", {
dispatcher: proxy,
headers: { authorization: `Bearer ${process.env.PARTNER_API_KEY}` },
});
console.log(res.status, await res.json());# pip install "httpx>=0.28" (proxy=; 0.28 removed proxies=)
import os
import httpx
with httpx.Client(proxy=os.environ["FIXEDMARK_PROXY_URL"], timeout=15) as client:
res = client.get("https://api.partner.example/v1/orders")
print(res.status_code, res.json())// Pass credentials as basicAuth instead of relying on URL userinfo.
const proxy = new URL(Deno.env.get("FIXEDMARK_PROXY_URL")!);
const client = Deno.createHttpClient({
proxy: {
url: `${proxy.protocol}//${proxy.host}`,
basicAuth: {
username: decodeURIComponent(proxy.username),
password: decodeURIComponent(proxy.password),
},
},
});
const res = await fetch("https://api.partner.example/v1/orders", { client });
console.log(res.status, await res.json());Related guides
- Integrationn8nFixed IPs for n8n HTTP Request nodes on n8n Cloud or self-hosted.
- IntegrationSupabase Edge FunctionsFixed outbound IPs for Supabase and Lovable Edge Functions with Deno's proxy client.
- IntegrationGitHub ActionsRoute deploy and sync steps through a fixed IP without self-hosted runners.
- Use casePartner API allowlistingGive Salesforce, SOAP vendors, and payment gateways one dedicated IP pair to allowlist, wherever your code runs.
- GuideFeaturesDestination allowlists, connection logs, and the bm tunnel CLI.
Frequently asked questions
How do I give an n8n workflow a static IP?
Open the HTTP Request node, add the Proxy option under Options, and paste your proxy URL. Requests from that node then leave from your static IP pair.
Can I use a static IP with Make or Zapier?
Only where the tool exposes a proxy setting. Otherwise call a small function you control, and have that function call the allowlisted API through Fixedmark.
Should my LLM API calls go through the proxy?
Usually not. Model providers do not need your static IP, and proxying them uses bandwidth. Proxy only the tools that call allowlisted systems.
How do I stop an agent from misusing the static IP?
Set a destination allowlist on the token so it can reach only approved hosts and ports, and review the connection logs.
Make it fixed.
Fixedmark is in early access. Join the list to get dedicated static IPs when your region opens.