MongoDB Atlas IP Whitelist for Serverless Apps
To whitelist a serverless app in MongoDB Atlas without opening it to 0.0.0.0/0, route the driver through a static IP and add that IP to the Atlas IP access list. The MongoDB Node.js driver supports SOCKS5 proxies natively, so you add two Fixedmark IPs as /32 entries and set four connection options.
Why serverless apps end up on 0.0.0.0/0
Atlas blocks every connection whose source IP is not on the project's IP access list. Serverless platforms such as Vercel, Netlify, and AWS Lambda run your functions on shared infrastructure with outbound IPs that change and are not published per project. The quick fix most tutorials suggest is adding 0.0.0.0/0, which allows the whole internet and leaves your cluster protected only by its password.
Atlas has private networking options, such as VPC peering and private endpoints, but they require your compute to run inside a cloud VPC you control. Functions on Vercel or Netlify do not. A static egress IP gives you a narrow allowlist without changing where your code runs.
How the SOCKS5 path works
The MongoDB Node.js driver accepts proxyHost, proxyPort, proxyUsername, and proxyPassword options and opens every connection through a SOCKS5 proxy. Install the socks package next to the driver. The driver still negotiates TLS directly with Atlas, so the proxy only forwards encrypted bytes and never sees your credentials or documents.
With a mongodb+srv:// connection string, the driver discovers all replica set members and connects to each one. Because every connection goes through the proxy, all of them leave from your Fixedmark IPs and match the access list.
Other drivers and the bm tunnel CLI
Drivers without SOCKS5 support can use the bm tunnel CLI, planned for launch, on platforms that run a long-lived process such as Railway, Render, Fly.io, or a VM. A tunnel forwards one local port to one remote host, so it suits a single node or a load-balanced endpoint. For an Atlas replica set, the driver connects to members by their real hostnames, which a single tunnel does not cover, so prefer a SOCKS5-capable driver for Atlas.
Whitelist a static IP in MongoDB Atlas
Do this once per Atlas project. Keep 0.0.0.0/0 until the new path is verified, then remove it.
Fixedmark is in early access. Proxy URLs are issued at launch. Join early access to get yours when your region opens.
- 1Get your Fixedmark pairPick the region closest to your Atlas cluster, for example Frankfurt for an EU cluster or Mumbai for an Atlas cluster in India.
- 2Add both IPs to the access listIn Atlas, open Network Access and add each IP as a /32 entry with a comment such as
fixedmark-egress. - 3Store the SOCKS URLAdd
FIXEDMARK_SOCKS_URLto your platform's environment variables next toMONGODB_URI. - 4Pass the proxy options to MongoClientParse the SOCKS URL and set the four proxy options. Create the client once per function instance and reuse it.
- 5Remove 0.0.0.0/0Deploy, confirm queries succeed, then delete the open entry from the access list.
// npm install mongodb socks
import { MongoClient } from "mongodb";
// FIXEDMARK_SOCKS_URL=socks5h://APP_ID:TOKEN@mum.egress.fixedmark.com:1080
const socks = new URL(process.env.FIXEDMARK_SOCKS_URL);
const client = new MongoClient(process.env.MONGODB_URI, {
proxyHost: socks.hostname,
proxyPort: Number(socks.port),
proxyUsername: decodeURIComponent(socks.username),
proxyPassword: decodeURIComponent(socks.password),
});
await client.connect();# Prints the IP the destination sees. Repeat it: each new connection
# leaves from one of the two IPs in your pair.
curl --proxy "$FIXEDMARK_PROXY_URL" https://fixedmark.com/api/ipSources
Checked October 2026. Confirm current details on the vendor's site before you decide. Prices and limits change.
Related guides
- IntegrationVercelFixed egress IPs for Vercel Functions without the $100 per project add-on.
- IntegrationNetlifyA fixed source IP for Netlify Functions without an Enterprise contract.
- IntegrationAWS LambdaA fixed IP for Lambda without VPC, subnets, and two NAT Gateways.
- Use casePostgres and MySQLAllowlist two IPs on RDS, Cloud SQL, or a self-hosted database and connect through SOCKS5 or a local tunnel.
Frequently asked questions
Is 0.0.0.0/0 in MongoDB Atlas safe?
It allows connection attempts from any IP on the internet, so your cluster is protected only by its credentials. A static egress IP lets you allow two addresses instead.
Does the MongoDB driver support proxies?
The Node.js driver supports SOCKS5 through the proxyHost, proxyPort, proxyUsername, and proxyPassword options, with the socks package installed.
Can Fixedmark read my MongoDB traffic?
No. The driver negotiates TLS directly with Atlas through the SOCKS5 tunnel, so the proxy forwards encrypted bytes only.
Which region should I choose?
Choose the Fixedmark region closest to your Atlas cluster to keep the added hop short. Launch regions are Mumbai, Singapore, Frankfurt, New York, and Virginia.
Make it fixed.
Fixedmark is in early access. Join the list to get dedicated static IPs when your region opens.