ZeroTwo runs in your browser and in native apps, and they all talk mainly to a handful of ZeroTwo-run addresses. On a school, office or VPN network that filters traffic, ask your network admin to allow the addresses below. Replies also stream over long-lived connections, which some proxies cut off.
Addresses to allow
| Address | What it is used for |
|---|---|
app.zerotwo.ai | The web app and its sign-in page. |
zerotwo.ai | The website: pricing, downloads, legal pages and the changelog. |
api.zerotwo.ai | ZeroTwo's API, used by the web app, the desktop app, ZeroTwo for iOS, ZeroTwo for Android and the browser extension. Allow both HTTPS and secure WebSockets (wss). |
db.zerotwo.ai | Account sign-in, your saved data and file storage, plus the live connection that keeps chats up to date. Allow HTTPS and secure WebSockets. |
files.zerotwo.ai | Processing of uploaded files. |
*.supabase.co | The provider address of the same account and storage service. The web app and the desktop app both list it next to db.zerotwo.ai as allowed, so allow it too if your network is strict. |
If your firewall can allow a whole domain, allow *.zerotwo.ai instead of listing hosts one by one.
Some features need a few more addresses. Sign-in with Google or Microsoft goes through those providers, the sign-in page can show a Cloudflare challenge (challenges.cloudflare.com), and paying for a plan or buying credits uses Stripe (js.stripe.com and api.stripe.com).
Let replies stream
ZeroTwo sends each answer as a stream of server-sent events from api.zerotwo.ai. The server asks proxies not to buffer the stream, and it sends a small keepalive message every 25 seconds. To keep replies from freezing or cutting off:
- Do not buffer or hold back responses from
api.zerotwo.ai. - Do not set an idle timeout shorter than 25 seconds, because that closes the connection even with the keepalive.
- Do not block WebSocket connections to
api.zerotwo.aianddb.zerotwo.ai. When a reply stream drops, ZeroTwo uses the live connection to catch up on what it missed.
What you may see on a blocked network
- A chat that will not open. A chat that cannot be loaded shows "We could not open this chat" with "Your chat history is safe. Try loading this chat again." and a Try again button. If your device itself reports no connection, the message is "You are offline" instead, with "Reconnect to the internet, then try opening this chat again."
- Upload failed. An attachment that could not be sent stays in the message box as a card that says "Upload failed", with a Retry button and a remove button labelled Remove failed file. If it keeps failing, check that
api.zerotwo.ai,db.zerotwo.aiandfiles.zerotwo.aiare reachable.
If a page still fails after the addresses are allowed, try the same chat on another network, such as a phone hotspot. If it works there, the first network is blocking something and your network admin can use this list to find it.