Skip to main content
Egress IP is an enterprise-only feature. Contact your account team to enable it for your account.
Egress IP shows the outbound IP addresses Neo uses when agents make external connections. Use these addresses to configure allowlists on firewalls, WAFs, or internal systems that restrict inbound traffic by source IP. Your static IP is shown in Settings → Egress IP.

Neo-managed cloud sandbox

Static. Outbound traffic from Neo sandbox terminals and tools originates from a fixed IP address. Add this to your allowlist to permit sandbox agent traffic.

Self-hosted sandbox

Outbound traffic from a self-hosted sandbox uses the host or network’s egress path, not Neo’s static sandbox IP. Allowlist the source address used by that host, VPN, proxy, or NAT gateway. If NEO_CONFINE_NETWORK=deny is active, confined commands have no network access and therefore produce no outbound traffic.

Browser

Dynamic. Outbound traffic from browser automation sessions does not use a static IP. No fixed address is available to allowlist for browser traffic.