Network and IP allowlists
If a firewall sits between Talkif and something you run — a SIP carrier, a webhook endpoint, an internal API — this is the page to hand your network team. Three kinds of traffic, three different sets of addresses; conflating them is the usual cause of “signalling works but there’s no audio” and “the webhook never arrives”.
Talkif’s endpoints (you → Talkif)
api.talkif.ai and app.talkif.ai are served from both regions behind standard HTTPS; there’s nothing to allowlist outbound beyond port 443 to those names.
SIP trunks (your carrier ↔ Talkif)
Signalling
Talkif sends outbound INVITEs from 63.176.211.13 and accepts inbound INVITEs to the same address on port 5060. Your carrier must allow this address; Talkif accepts inbound SIP only from the carrier IPs/CIDRs listed on your SIP provider in the dashboard. Talkif does not REGISTER with your carrier.
Media (RTP)
RTP does not flow through the signalling address. Talkif’s trunking is bridged through its carrier’s media edges in Frankfurt and Ashburn, and audio is exchanged directly with those. If your carrier filters RTP by source, allow the published media ranges for those two edges — Twilio’s SIP IP address list is the authoritative source and changes occasionally. Symptom of getting this wrong: calls connect, nobody hears anything (or only one side does).
Full setup in Bring your own SIP trunk; how the edge is chosen in Regions and edges.
Webhooks and flow functions (Talkif → you)
HTTPS requests from Talkif to your endpoints — flow functions called during a call — leave through a single fixed egress address per region (EU and US). They are the addresses to allowlist if your endpoint isn’t open to the internet.
The current addresses are provided by support on request and confirmed in writing, so that a change is communicated rather than discovered. Two things to design in regardless of source IP:
- Verify the
Talkif-Signatureheader on every request — Webhooks. An allowlist proves where a request came from; the signature proves who sent it and that it’s intact. - Allow both regions. A call served from the US region calls your endpoint from the US egress address even if your account “lives” in the EU.
Requests are made only to public addresses: private ranges (10/8, 172.16/12, 192.168/16), loopback, link-local and cloud-metadata addresses are refused, and hostnames resolving to any such address are refused too. Redirects are not followed.