The hostnames a user’s browser must reach for the agronome.ai platform to work behind a restrictive corporate firewall or proxy. Clearing agronome.ai alone is not enough — the app loads content and uploads imagery directly from several Google and mapping hosts.
Image upload sends file data straight from the browser to Google Cloud Storage, not through agronome.ai. If this one host is blocked, the app opens and everything else works — but uploads stall or fail. It is the single most common symptom.
storage.googleapis.comProxy blocks this host by category or won’t allow a wildcard? See the path-scoped URLs below.
Checks whether this browser can reach each required host on your current network. Run it after your firewall or proxy changes — anything marked red is still blocked. Testing the production environment.
storage.googleapis.comCloud Storage host — image uploads & downloadsidentitytoolkit.googleapis.comLogin (email / password)securetoken.googleapis.comSession token refreshagronome-platform-prod.firebaseapp.comFirebase auth handlertiles.openfreemap.orgStreet basemapserver.arcgisonline.comSatellite basemapphoton.komoot.ioAddress searchfonts.gstatic.comWeb fontsBest-effort from the browser: green means the host responded, red means the connection was blocked or failed. The storage row tests the storage.googleapis.com host — a proxy that allows only specific bucket paths may still show it red, so confirm uploads directly. Cross-origin rules hide response details, so a proxy’s “block page” can occasionally read as reachable; if uploads fail with everything green, capture the browser’s DevTools → Network tab.
Allow all of these. Block any one and a core feature — login, uploads, or maps — breaks for every user.
agronome.aiwww.agronome.aiusually already clearedThe web app and its backend API (served same-origin at /api).
If blocked: Nothing loads.
staging.agronome.aistaging onlyStaging environment — only if this user works in staging.
If blocked: Staging will not load.
identitytoolkit.googleapis.comEmail/password login, sign-up, and password reset.
If blocked: Cannot log in at all.
securetoken.googleapis.comRefreshes the session token in the background.
If blocked: Logged out every few minutes; intermittent 401 errors.
agronome-platform-prod.firebaseapp.comagronome-platform-dev.firebaseapp.comFirebase authentication handler (production / staging respectively).
If blocked: Login handshake fails.
storage.googleapis.comDirect browser upload of drone & import imagery (resumable PUT), plus download of processed imagery, report PDFs, and prescription / shapefile exports.
If blocked: Uploads fail; exports and processed imagery will not download. Proxies that block this host by category need the exact per-bucket URLs below.
tiles.openfreemap.orgDefault street basemap (map tiles, labels, sprites).
If blocked: Blank map in street view.
server.arcgisonline.comDefault satellite basemap (Esri World Imagery).
If blocked: Blank map in satellite view.
photon.komoot.ioAddress search / location autocomplete.
If blocked: Address search returns nothing.
fonts.googleapis.comfonts.gstatic.comrecommendedWeb fonts (Inter, Space Grotesk).
If blocked: Cosmetic only — the app falls back to system fonts.
Only needed when the listed capability is turned on for this user or organization.
accounts.google.comapis.google.com"Sign in with Google" popup.
When: Only if users log in with Google instead of email + password.
login.microsoftonline.comlogin.live.com"Sign in with Microsoft" popup.
When: Only if users log in with Microsoft.
www.google.comwww.gstatic.comreCAPTCHA (login abuse protection, if enforced).
When: If login fails only on this network, allow the /recaptcha/ paths on these hosts.
signin.johndeere.comconnections.deere.comJohn Deere Operations Center — sign-in and account-grant redirects.
When: Both are browser redirects during "Connect", so allow both. May also load *.oktacdn.com.
identity.cnhind.comCNH Industrial / FieldOps (Case IH, New Holland) sign-in.
When: Staging uses stg.identity.cnhind.com.
onelogin.agcocorp.comwww.farmengage.comAGCO / PTX FarmENGAGE — sign-in and account-grant redirects.
When: Both are browser redirects during "Connect", so allow both. May also load *.b2clogin.com, aadcdn.msftauth.net.
api.mapbox.comMapbox basemaps, when a user supplies their own token in Settings.
When: Off by default — only if a user switches the map provider to Mapbox.
www.google.com"Open route in Google Maps" links from the flight schedule.
When: Opens Google Maps in a new tab.
docs.agronome.aiIn-app help & documentation links.
When: Documentation links will not open.
These run server-side; their data reaches the browser proxied through agronome.ai. No need to open them.
Satellite imagery providers(Sentinel Hub / Copernicus, Planet Labs)Satellite imagery.
Why it’s fine: Fetched by our backend and served to the browser through agronome.ai/api (same origin). The browser never contacts these providers directly.
*.deere.com, api.farmengage.comCNH data APIsEquipment data sync.
Why it’s fine: Runs on our servers. Only the vendor sign-in page (listed above) is browser-facing.
DJI CloudDrone fleet management.
Why it’s fine: Handled on the drone controller device and our backend — not the user’s computer browser.
Uploads and downloads use a single fixed host — storage.googleapis.com — with your organization’s storage bucket in the URL path. A proxy that blocks the host by category and can’t use a * wildcard can allow just these path prefixes instead. All HTTPS on TCP 443.
# Image uploads (resumable) — the request a blocked proxy reports: https://storage.googleapis.com/upload/storage/v1/b/<bucket>/o # Downloads + attachment uploads: https://storage.googleapis.com/<bucket>/
Email security@agronome.ai and we’ll send the exact bucket names for your environment (staging or production) to drop into the <bucket> segment.
Where wildcard domains are permitted, these cover everything required in one shot — all over HTTPS on TCP 443. If your policy forbids * (common in enterprise), skip this and use the path-scoped Cloud Storage URLs above plus the specific hosts in each section.
# App + API (usually already cleared) agronome.ai *.agronome.ai # Google: Cloud Storage (uploads) + Firebase Auth (login). One wildcard covers # storage.googleapis.com, identitytoolkit.googleapis.com, securetoken.googleapis.com *.googleapis.com *.firebaseapp.com *.gstatic.com # Maps + address search + fonts tiles.openfreemap.org server.arcgisonline.com photon.komoot.io fonts.googleapis.com
On the affected machine, open the app, then open the browser’s Developer Tools → Network tab and reproduce the failing action (upload, login, etc.).
Proxies that do TLS/SSL inspection can also break uploads even when the host is allowed — exempting storage.googleapis.com from interception usually resolves it.
Email security@agronome.ai and we’ll share data-flow diagrams or the relevant contract terms.
View sub-processor list