Back to Security & Trust
Network configuration · IT team

Enterprise network allowlist

The hostnames a user’s browser must reach for the agronome.ai platform to work behind a restrictive corporate firewall or proxy. Clearing agronome.ai alone is not enough — the app loads content and uploads imagery directly from several Google and mapping hosts.

Applies to: the web app at agronome.ai (and staging.agronome.ai)Protocol: HTTPS · TCP 443Last reviewed: July 2026

Uploads failing? Start here.

Image upload sends file data straight from the browser to Google Cloud Storage, not through agronome.ai. If this one host is blocked, the app opens and everything else works — but uploads stall or fail. It is the single most common symptom.

storage.googleapis.com

Proxy blocks this host by category or won’t allow a wildcard? See the path-scoped URLs below.

Self-serve check

Test connectivity from this machine

Checks whether this browser can reach each required host on your current network. Run it after your firewall or proxy changes — anything marked red is still blocked. Testing the production environment.

  • storage.googleapis.comCloud Storage host — image uploads & downloads
  • identitytoolkit.googleapis.comLogin (email / password)
  • securetoken.googleapis.comSession token refresh
  • agronome-platform-prod.firebaseapp.comFirebase auth handler
  • tiles.openfreemap.orgStreet basemap
  • server.arcgisonline.comSatellite basemap
  • photon.komoot.ioAddress search
  • fonts.gstatic.comWeb fonts

Best-effort from the browser: green means the host responded, red means the connection was blocked or failed. The storage row tests the storage.googleapis.com host — a proxy that allows only specific bucket paths may still show it red, so confirm uploads directly. Cross-origin rules hide response details, so a proxy’s “block page” can occasionally read as reachable; if uploads fail with everything green, capture the browser’s DevTools → Network tab.

Required

Allow all of these. Block any one and a core feature — login, uploads, or maps — breaks for every user.

Application & API

agronome.aiwww.agronome.aiusually already cleared

The web app and its backend API (served same-origin at /api).

If blocked: Nothing loads.

staging.agronome.aistaging only

Staging environment — only if this user works in staging.

If blocked: Staging will not load.

Sign-in — Firebase Authentication

identitytoolkit.googleapis.com

Email/password login, sign-up, and password reset.

If blocked: Cannot log in at all.

securetoken.googleapis.com

Refreshes the session token in the background.

If blocked: Logged out every few minutes; intermittent 401 errors.

agronome-platform-prod.firebaseapp.comagronome-platform-dev.firebaseapp.com

Firebase authentication handler (production / staging respectively).

If blocked: Login handshake fails.

Image upload & file download — Google Cloud Storage

storage.googleapis.com

Direct browser upload of drone & import imagery (resumable PUT), plus download of processed imagery, report PDFs, and prescription / shapefile exports.

If blocked: Uploads fail; exports and processed imagery will not download. Proxies that block this host by category need the exact per-bucket URLs below.

Maps & address search

tiles.openfreemap.org

Default street basemap (map tiles, labels, sprites).

If blocked: Blank map in street view.

server.arcgisonline.com

Default satellite basemap (Esri World Imagery).

If blocked: Blank map in satellite view.

photon.komoot.io

Address search / location autocomplete.

If blocked: Address search returns nothing.

fonts.googleapis.comfonts.gstatic.comrecommended

Web fonts (Inter, Space Grotesk).

If blocked: Cosmetic only — the app falls back to system fonts.

Conditional

Only needed when the listed capability is turned on for this user or organization.

Single sign-on

accounts.google.comapis.google.com

"Sign in with Google" popup.

When: Only if users log in with Google instead of email + password.

login.microsoftonline.comlogin.live.com

"Sign in with Microsoft" popup.

When: Only if users log in with Microsoft.

www.google.comwww.gstatic.com

reCAPTCHA (login abuse protection, if enforced).

When: If login fails only on this network, allow the /recaptcha/ paths on these hosts.

Equipment integrations

signin.johndeere.comconnections.deere.com

John Deere Operations Center — sign-in and account-grant redirects.

When: Both are browser redirects during "Connect", so allow both. May also load *.oktacdn.com.

identity.cnhind.com

CNH Industrial / FieldOps (Case IH, New Holland) sign-in.

When: Staging uses stg.identity.cnhind.com.

onelogin.agcocorp.comwww.farmengage.com

AGCO / PTX FarmENGAGE — sign-in and account-grant redirects.

When: Both are browser redirects during "Connect", so allow both. May also load *.b2clogin.com, aadcdn.msftauth.net.

Optional convenience features

api.mapbox.com

Mapbox basemaps, when a user supplies their own token in Settings.

When: Off by default — only if a user switches the map provider to Mapbox.

www.google.com

"Open route in Google Maps" links from the flight schedule.

When: Opens Google Maps in a new tab.

docs.agronome.ai

In-app help & documentation links.

When: Documentation links will not open.

Not needed

These run server-side; their data reaches the browser proxied through agronome.ai. No need to open them.

Not needed on user machines

Satellite imagery providers(Sentinel Hub / Copernicus, Planet Labs)

Satellite imagery.

Why it’s fine: Fetched by our backend and served to the browser through agronome.ai/api (same origin). The browser never contacts these providers directly.

*.deere.com, api.farmengage.comCNH data APIs

Equipment data sync.

Why it’s fine: Runs on our servers. Only the vendor sign-in page (listed above) is browser-facing.

DJI Cloud

Drone fleet management.

Why it’s fine: Handled on the drone controller device and our backend — not the user’s computer browser.

No-wildcard allowlists

Cloud Storage without a wildcard

Uploads and downloads use a single fixed host — storage.googleapis.com — with your organization’s storage bucket in the URL path. A proxy that blocks the host by category and can’t use a * wildcard can allow just these path prefixes instead. All HTTPS on TCP 443.

Path prefixes to allow
# Image uploads (resumable) — the request a blocked proxy reports:
https://storage.googleapis.com/upload/storage/v1/b/<bucket>/o
# Downloads + attachment uploads:
https://storage.googleapis.com/<bucket>/

Email security@agronome.ai and we’ll send the exact bucket names for your environment (staging or production) to drop into the <bucket> segment.

Shortcut

If your proxy allows wildcards

Where wildcard domains are permitted, these cover everything required in one shot — all over HTTPS on TCP 443. If your policy forbids * (common in enterprise), skip this and use the path-scoped Cloud Storage URLs above plus the specific hosts in each section.

Minimum required
# App + API (usually already cleared)
agronome.ai
*.agronome.ai
# Google: Cloud Storage (uploads) + Firebase Auth (login). One wildcard covers
# storage.googleapis.com, identitytoolkit.googleapis.com, securetoken.googleapis.com
*.googleapis.com
*.firebaseapp.com
*.gstatic.com
# Maps + address search + fonts
tiles.openfreemap.org
server.arcgisonline.com
photon.komoot.io
fonts.googleapis.com

If something still fails

On the affected machine, open the app, then open the browser’s Developer Tools → Network tab and reproduce the failing action (upload, login, etc.).

  1. Look for requests marked (blocked), failed, or stuck pending.
  2. Note the domain of each — that is a host the firewall or proxy is still stopping.
  3. Send us the list and we’ll confirm which are ours.

Proxies that do TLS/SSL inspection can also break uploads even when the host is allowed — exempting storage.googleapis.com from interception usually resolves it.

Questions about any host on this list?

Email security@agronome.ai and we’ll share data-flow diagrams or the relevant contract terms.

View sub-processor list