Firewall Allowlist Requirements for Client IT Teams

Created by David Nickolls, Modified on Fri, 19 Jun at 11:47 AM by Dimi

For client IT teams. This document lists every external service that a VIDA application contacts from the end-user's browser. All traffic is outbound over HTTPS port 443 unless stated otherwise.

firewall allowlist network IT setup Aspera SSO

Only production endpoints are listed. Please contact VIDA support if you also need staging environment addresses.

Which apps are you deploying?

AppURLNotes
VIDAapp.vida.studioMain operator interface
Launchpadlaunchpad.vida.studioSupplier upload portal
Storefront*.storefront.vida.studioCustomer-facing delivery portal
Connect2*.connect2.vida.studioRights-managed distribution portal
Premiere PanelAdobe desktop extensionVIDA inside Adobe Premiere Pro


Required for all apps

These must be allowed regardless of which VIDA app(s) you are deploying.

Tip for IT teams: If your firewall supports wildcard rules, a single *.vida.studio rule covers all first-level VIDA subdomains (e.g. api.vida.studio, player.vida.studio). You will still need separate rules for player.launchpad.vida.studio, *.storefront.vida.studio, and *.connect2.vida.studio as these are deeper subdomains not matched by a single wildcard level.

DestinationPortPurpose
api.vida.studio443VIDA application API
*.googleapis.com443Google services (authentication, fonts)
*.firebaseapp.com443Firebase authentication
*.web.app443Firebase authentication
us-central1-vida-prd.cloudfunctions.net443Multi-factor authentication (passkey)
player.vida.studio443Media thumbnails and video playback (CDN)
accounts.google.com443Google Sign-In
fonts.gstatic.com443Application fonts


Required per app


VIDA (app.vida.studio) — additional requirements

DestinationPortPurpose
*.execute-api.eu-west-1.amazonaws.com443Real-time notifications (WebSocket)
maps.googleapis.com443Google Maps (already covered by *.googleapis.com)


Launchpad (launchpad.vida.studio) — additional requirements

DestinationPortPurpose
*.execute-api.eu-west-1.amazonaws.com443Real-time notifications (WebSocket)
player.launchpad.vida.studio443Attachment and preview playback


Connect2 (*.connect2.vida.studio) — no additional requirements


Storefront (*.storefront.vida.studio) — no additional requirements


Premiere Panel — additional requirements

DestinationPortPurpose
*.execute-api.eu-west-1.amazonaws.com443Real-time notifications (WebSocket)


File transfer — IBM Aspera

Applies to: VIDA, Launchpad, Connect2 only.

Aspera uses its own protocol (FASP) on a non-standard port. Both TCP and UDP must be open on port 33001 to the following servers:

Tip for IT teams: We recommend allowing *.vidatx.net on port 33001 (TCP and UDP) rather than individual hostnames. This covers all current transfer servers and ensures uninterrupted access if additional nodes are added in future.

DestinationTCP 33001UDP 33001Purpose
ams-1.vidatx.netSession setup + high-speed transfer
ams-2.vidatx.netSession setup + high-speed transfer
ams-3.vidatx.netSession setup + high-speed transfer
artemis.vidatx.netSession setup + high-speed transfer


Conditional requirements

These are only needed if your organisation uses the listed feature.

FeatureDestinationPortApplies to
Microsoft / Entra ID loginlogin.microsoftonline.com443All apps (if Microsoft SSO is enabled)
Microsoft / Entra ID loginlogin.live.com443All apps (if Microsoft SSO is enabled)
Okta login*.okta.com443VIDA, Launchpad, Storefront, Connect2 (if Okta SSO is enabled)
Okta loginYour custom Okta domain443If your organisation uses a custom Okta domain


Email delivery

Passwordless login sends a one-time sign-in link to the user's email address. Ensure your email filtering and spam policies allow delivery from:

  • noreply@vida.studio (or the Firebase sender address configured for your account)

No firewall rule is required — the link is clicked in the browser over standard HTTPS.


What you do NOT need to allow

The following are loaded by VIDA apps but are not required for functionality and can be blocked safely:

ServiceDomainNotes
Google Tag Managerwww.googletagmanager.comAnalytics — fails silently when blocked
Google Analyticsregion1.google-analytics.comAnalytics — fails silently when blocked

Was this article helpful?

That’s Great!

Thank you for your feedback

Sorry! We couldn't be helpful

Thank you for your feedback

Let us know how can we improve this article!

Select at least one of the reasons
CAPTCHA verification is required.

Feedback sent

We appreciate your effort and will try to fix the article