Static IP for SFTP Allowlisting From Serverless Apps
Banks, payroll providers, retailers, and logistics partners often run SFTP servers that only accept connections from allowlisted IPs. Connect through a static IP pair using SOCKS5 in your SFTP library, or the planned bm tunnel CLI on long-lived services, and give the partner both addresses. SSH encryption and host key checks still run end to end.
Who still asks for an SFTP allowlist
File drops over SFTP are still the norm for batch integrations. The server's firewall usually opens port 22 only to IPs on the partner's list:
- Bank host-to-host links for payment files, statements, and reconciliation reports.
- Payroll, benefits, and HR providers that exchange employee files.
- Retail and logistics EDI exchanges for orders, invoices, and shipment notices.
- Data vendors and enterprise customers that push or pull nightly exports.
Choose a connection path
SOCKS5 works anywhere, including serverless functions. Node's ssh2 and ssh2-sftp-client accept an already-open socket through the sock option, which you can open with the socks package. Python's paramiko also takes a sock argument, which PySocks can provide. In Go, dial through golang.org/x/net/proxy and pass the connection to ssh.NewClientConn.
The planned bm tunnel CLI forwards a local port to the SFTP server through your Fixedmark IPs. It suits long-lived services on Railway, Render, Fly.io, or a VM, and the sftp command line tool. Set OpenSSH's HostKeyAlias to the real hostname so host key checks still match.
Plan for function time limits
Large file transfers can outlast a serverless function's maximum duration. If your files are big or the partner's server is slow, run transfers from a background worker or a scheduled job on a long-lived service, and keep functions for small files.
This page covers SFTP. Classic FTP and FTPS open separate data connections on other ports, so they need a client that sends both the control and data connections through SOCKS5. Ask the partner whether SFTP is available first.
Allowlist a static IP with an SFTP partner
Keep the existing path working until the partner confirms the new IPs.
Fixedmark is in early access. Proxy URLs are issued at launch. Join early access to get yours when your region opens.
- 1Create a pair near the serverChoose the region closest to the partner's SFTP host, for example Mumbai for an Indian bank's host-to-host server.
- 2Send both IPs to the partnerAsk them to allow both addresses on the SFTP port. Send your SSH public key in the same request if they need one.
- 3Store the SOCKS URLSet
FIXEDMARK_SOCKS_URLon your platform. For the tunnel path, the CLI reads its token from its own config. - 4Connect through SOCKS5 or the tunnelPass a proxied socket to your SFTP library, or start
bm tunneland connect to the local port withHostKeyAliasset. - 5Pin the host key and verifyKeep strict host key checking on. Confirm the first transfer in the connection log, then remove any old allowlist entries.
// npm install ssh2-sftp-client socks
import SftpClient from "ssh2-sftp-client";
import { SocksClient } from "socks";
const socks = new URL(process.env.FIXEDMARK_SOCKS_URL);
const host = "sftp.partner.example";
// Open the TCP connection through your Fixedmark IPs.
const { socket } = await SocksClient.createConnection({
proxy: {
host: socks.hostname,
port: Number(socks.port),
type: 5,
userId: decodeURIComponent(socks.username),
password: decodeURIComponent(socks.password),
},
command: "connect",
destination: { host, port: 22 },
});
// SSH runs over that socket, end to end with the partner.
const sftp = new SftpClient();
await sftp.connect({
sock: socket,
host,
username: "acme",
privateKey: process.env.SFTP_PRIVATE_KEY,
});
await sftp.put("./settlement.csv", "/inbound/settlement.csv");
await sftp.end();# pip install paramiko PySocks
import os
from urllib.parse import unquote, urlparse
import paramiko
import socks
u = urlparse(os.environ["FIXEDMARK_SOCKS_URL"])
host = "sftp.partner.example"
sock = socks.socksocket()
sock.set_proxy(socks.SOCKS5, u.hostname, u.port, rdns=True,
username=unquote(u.username), password=unquote(u.password))
sock.connect((host, 22))
client = paramiko.SSHClient()
client.load_system_host_keys() # Unknown host keys are rejected.
client.connect(host, username="acme",
key_filename="/secrets/sftp_key", sock=sock)
sftp = client.open_sftp()
sftp.put("settlement.csv", "/inbound/settlement.csv")
client.close()# Forward local port 2222 to the partner's SFTP server through your Fixedmark IPs.
bm tunnel 2222:sftp.partner.example:22 &
# HostKeyAlias checks the partner's real host key, not one for 127.0.0.1.
sftp -P 2222 -o HostKeyAlias=sftp.partner.example acme@127.0.0.1Sources
Checked October 2026. Confirm current details on the vendor's site before you decide. Prices and limits change.
Related guides
- Use casePartner API allowlistingGive Salesforce, SOAP vendors, and payment gateways one dedicated IP pair to allowlist, wherever your code runs.
- Use caseBank and UPI APIsWhitelist one dedicated IP pair with your bank, UPI partner bank, or GSP, then deploy on Vercel or Railway without re-whitelisting.
- Use casePostgres and MySQLAllowlist two IPs on RDS, Cloud SQL, or a self-hosted database and connect through SOCKS5 or a local tunnel.
- IntegrationRailwayA dedicated IP pair for Railway services when shared static IPs are not enough.
- IntegrationAWS LambdaA fixed IP for Lambda without VPC, subnets, and two NAT Gateways.
- ComparisonQGTunnel alternativeHow QuotaGuard's QGTunnel works, where its transparent mode helps or hurts, and the SOCKS5 and tunnel alternatives.
Frequently asked questions
How do I connect to an IP-allowlisted SFTP server from AWS Lambda?
Open the TCP connection through a SOCKS5 proxy with a static IP and pass that socket to your SFTP library, such as ssh2-sftp-client or paramiko. Then ask the partner to allow the proxy's IPs.
Does host key verification still work through a proxy?
Yes. SSH runs end to end between your client and the server, so the server presents its real host key. With a local tunnel, set HostKeyAlias to the real hostname so the check matches.
Can the proxy see my files?
No. The proxy forwards SSH's encrypted bytes. It logs the destination, bytes, and result of each connection, not file names or contents.
Does this work for FTP or FTPS?
Only with a client that sends both the control and data connections through SOCKS5. SFTP uses one connection, which makes it much simpler to route through a static IP.
Make it fixed.
Fixedmark is in early access. Join the list to get dedicated static IPs when your region opens.