Skip to main content

Atlan Network Details

Connect docs via MCP

Atlan connects to your data sources using a fixed set of network identities - public egress IPs, private CIDR ranges, and endpoint identities. This page lists the values for GCP. AWS and Azure values are specific to your tenant and can be requested through a support ticket.

Which value applies to me?

Your setupAllowlist thisWhere to get it
Public connectivity (no private link)Public egress (NAT) IPs for your tenantGCP: table below · AWS/Azure: support ticket
Private Link, and your data source enforces an IP network policyPrivate CIDR ranges for your tenant and not the public IPsSupport ticket (shared during Private Link setup)
Private Link, allowlisting by identity instead of IPThe endpoint identity (more robust as it survives IP changes)Support ticket (shared during Private Link setup)
The #1 misconfiguration

When connecting over a private link, connections originate from Atlan's private CIDR ranges, not the public egress IPs.

Always allowlist the complete CIDR range. Traffic rotates across addresses within the block, so a partial allowlist can cause intermittent failures that only appear at certain times of day.

AWS-hosted Atlan tenants

NAT IPs, private CIDR ranges, and endpoint identities for AWS-hosted tenants are provisioned per tenant and differ from tenant to tenant.

Raise a support request from within Atlan with your tenant URL and ask for your tenant's network details. Support responds with:

  • Public egress (NAT) IPs - for standard IP allowlisting
  • Private CIDR ranges - for network policies enforced over Private Link
  • Endpoint identity (VPCE ID) - for identity-based allowlisting
tip

Ask for all three in one ticket, even if you only need one today—it saves a second round-trip when your security team asks later.

Azure-hosted Atlan tenants

NAT IPs, private CIDR ranges, and endpoint identities for Azure-hosted tenants are provisioned per tenant and differ from tenant to tenant.

Raise a support request from within Atlan with your tenant URL and ask for your tenant's network details. Support responds with:

  • Public egress (NAT) IPs - for standard IP allowlisting
  • Private CIDR ranges - for network policies enforced over Private Link

The private endpoint Resource ID is shared during Private Link setup.

GCP-hosted Atlan tenants

GCP tenants use static outbound NAT IPs (public connectivity only—Private Link to Snowflake isn't available on GCP). Self-serve: allowlist the IPs for your tenant's region.

RegionStatic NAT IPs to allowlist
us-west1136.117.155.120, 34.127.41.4
us-east134.26.52.81, 34.73.83.0, 34.26.163.142, 34.74.21.241, 35.243.183.24, 35.231.129.67, 35.237.234.69, 35.196.195.255, 34.74.28.5
us-east434.86.129.151, 34.48.123.67, 34.48.217.146, 34.48.102.77, 8.228.117.82, 136.107.79.249, 35.245.178.215, 34.86.10.10, 8.228.109.175, 34.21.77.175
us-central134.132.15.38, 34.123.140.247, 35.222.5.222, 34.70.17.75, 35.184.242.149, 34.16.87.188, 34.55.30.78, 34.31.216.119, 136.119.202.26, 34.10.169.203
europe-west135.233.44.61, 35.195.95.186, 34.53.232.244
europe-west235.197.251.238, 34.142.108.148, 34.142.84.105, 35.189.77.235
europe-west335.234.127.28, 34.159.63.41, 34.40.10.31
europe-west434.6.83.67, 34.13.219.159
europe-north135.228.230.216, 34.88.181.71

Allowlist all IPs listed for your region. See also Allowlisting Atlan IPs in Snowflake.

Change management

  • Atlan gives at least 30 days' notice before any published value changes, via email to tenant admins and a changelog entry on this page.
  • Changes are scheduled in announced maintenance windows; the old and new values overlap during the window so a timely update means zero downtime.
  • If a connector suddenly fails with a network-policy error and nothing changed on your side, check the changelog below first.

Changelog

DateChange
2026-02-27GCP regions migrated from dynamic to static dedicated NAT IPs. Dynamic IPs retired.
2026-01-05Initial publication of this page.