# Which network addresses does ZeroTwo need to connect?

> Allow ZeroTwo's web, API, database and streaming addresses on your firewall or proxy, and see what a blocked network looks like in the app.

Source: https://help.zerotwo.ai/en/articles/9247338-which-network-addresses-does-zerotwo-need-to-connect
Section: ZeroTwo
Last updated: 2026-10-05

ZeroTwo runs in your browser and in native apps, and they all talk mainly to a handful of ZeroTwo-run addresses. On a school, office or VPN network that filters traffic, ask your network admin to allow the addresses below. Replies also stream over long-lived connections, which some proxies cut off.

## Addresses to allow

| Address | What it is used for |
| --- | --- |
| `app.zerotwo.ai` | The web app and its sign-in page. |
| `zerotwo.ai` | The website: pricing, downloads, legal pages and the changelog. |
| `api.zerotwo.ai` | ZeroTwo's API, used by the web app, the desktop app, ZeroTwo for iOS, ZeroTwo for Android and the browser extension. Allow both HTTPS and secure WebSockets (wss). |
| `db.zerotwo.ai` | Account sign-in, your saved data and file storage, plus the live connection that keeps chats up to date. Allow HTTPS and secure WebSockets. |
| `files.zerotwo.ai` | Processing of uploaded files. |
| `*.supabase.co` | The provider address of the same account and storage service. The web app and the desktop app both list it next to `db.zerotwo.ai` as allowed, so allow it too if your network is strict. |

If your firewall can allow a whole domain, allow `*.zerotwo.ai` instead of listing hosts one by one.

Some features need a few more addresses. Sign-in with Google or Microsoft goes through those providers, the sign-in page can show a Cloudflare challenge (`challenges.cloudflare.com`), and paying for a plan or buying credits uses Stripe (`js.stripe.com` and `api.stripe.com`).

## Let replies stream

ZeroTwo sends each answer as a stream of server-sent events from `api.zerotwo.ai`. The server asks proxies not to buffer the stream, and it sends a small keepalive message every 25 seconds. To keep replies from freezing or cutting off:

- Do not buffer or hold back responses from `api.zerotwo.ai`.
- Do not set an idle timeout shorter than 25 seconds, because that closes the connection even with the keepalive.
- Do not block WebSocket connections to `api.zerotwo.ai` and `db.zerotwo.ai`. When a reply stream drops, ZeroTwo uses the live connection to catch up on what it missed.

## What you may see on a blocked network

- **A chat that will not open.** A chat that cannot be loaded shows "We could not open this chat" with "Your chat history is safe. Try loading this chat again." and a **Try again** button. If your device itself reports no connection, the message is "You are offline" instead, with "Reconnect to the internet, then try opening this chat again."
- **Upload failed.** An attachment that could not be sent stays in the message box as a card that says "Upload failed", with a **Retry** button and a remove button labelled Remove failed file. If it keeps failing, check that `api.zerotwo.ai`, `db.zerotwo.ai` and `files.zerotwo.ai` are reachable.

![An attachment card in the ZeroTwo message box that says Upload failed, with a Retry button.](https://help.zerotwo.ai/images/zerotwo/9247338-network-recommendations-for-zerotwo-errors-on-web-and-apps/01-error-banner-stating-failed-upload-to-files-uploads.png)

If a page still fails after the addresses are allowed, try the same chat on another network, such as a phone hotspot. If it works there, the first network is blocking something and your network admin can use this list to find it.
