AI Agents and Firewall Whitelisting: Static IPs for LLM-Powered Workflows

QuotaGuard Engineering
September 18, 2026
•
5 min read
Pattern

Give your AI application's protected API calls a managed, stable outbound identity with QuotaGuard. Route the calls that need IP allowlisting through your assigned pair while QuotaGuard operates the proxy infrastructure, monitoring, maintenance, and failover. Your team can build the agent's tools without taking on a proxy VM or NAT deployment just to satisfy a client's firewall.

The important connection is the one your application opens to the protected destination. An agent deciding to use a tool does not automatically give that tool a stable source address. Configure the HTTP client inside the tool, retain the destination's authentication, and ask its administrator to allowlist both QuotaGuard addresses.

Follow the Tool's Outbound Connection

A customer-controlled worker might read a CRM, call a partner API, and update a database during one task. An IP restriction on any of those connections can interrupt the workflow even when its credentials are correct. A 403 or timeout alone does not prove the source IP is the cause; use the destination's access policy and logs to confirm the rejected connection.

For an HTTPS tool, the intended route is:

customer-controlled tool client → QuotaGuard → approved partner API

If a SaaS vendor's server opens the protected connection instead, setting a proxy in your own application does not reroute that vendor's traffic. Identify the process making the call before choosing its configuration.

Why Use Managed Egress for Agent Tools?

QuotaGuard handles the availability, load balancing, maintenance, and support of the proxy infrastructure. Your application keeps a portable source identity across supported runtimes, and you can route selected clients without pushing every unrelated request through the same proxy.

Some hosting platforms offer native static egress or a VPC/NAT path. Those options have their own plan, scope, routing, and operational requirements. QuotaGuard is the managed application-level choice when you want a small stable allowlist, selective routing, portability, and engineering support without owning the egress infrastructure.

Your team still owns the agent application, its tool permissions, and its destination credentials. A fixed source address is not a sandbox boundary or proof that an agent's requested action is safe.

Node.js: Configure the Fetch Client You Actually Import

This example targets Node.js 24 and explicitly imports node-fetch. Save it as partner-tool.mjs and install:

npm install --save-exact node-fetch@3.3.2 https-proxy-agent@9.1.0

Supply QUOTAGUARDSTATIC_URL, PARTNER_API_URL, and PARTNER_API_TOKEN through server-side runtime secrets/configuration. The URL should identify a developer-approved, read-only HTTPS endpoint that returns JSON. This sample uses bearer authentication; adapt that header to the partner's actual requirements.

import fetch from 'node-fetch';
import { HttpsProxyAgent } from 'https-proxy-agent';

function required(name) {
  const value = process.env[name];
  if (!value) throw new Error(`${name} is required`);
  return value;
}

const endpoint = new URL(required('PARTNER_API_URL'));
if (endpoint.protocol !== 'https:' || endpoint.username || endpoint.password) {
  throw new Error('Use a configured HTTPS endpoint without URL credentials');
}
const token = required('PARTNER_API_TOKEN');
const agent = new HttpsProxyAgent(required('QUOTAGUARDSTATIC_URL'));

export async function callPartnerAPI() {
  const response = await fetch(endpoint, {
    agent,
    headers: { Authorization: `Bearer ${token}` },
    signal: AbortSignal.timeout(15000),
    redirect: 'error',
    size: 1024 * 1024,
  });
  if (!response.ok) {
    response.body?.destroy();
    throw new Error(`Partner API returned HTTP ${response.status}`);
  }
  return response.json();
}

Wire this function into your application's tool implementation. The destination is chosen by your configuration, not supplied as an arbitrary URL by the model. Redirects are rejected rather than silently sending the tool to another endpoint. Reuse the agent for the worker's requests and destroy it when shutting down the worker.

This is not Node's global fetch. The imported node-fetch client supports agent. Native Node fetch uses an Undici-compatible dispatcher. For a node:https example without the fetch package, use our Node.js proxy guide.

Python: Give the Tool an Explicit Proxy Session

For a Python tool using Requests, configure the session that the tool actually calls. Supply the same three runtime values as above and install Requests in your application's environment.

import os
from urllib.parse import urlsplit
import requests

proxy_url = os.environ["QUOTAGUARDSTATIC_URL"]
endpoint = os.environ["PARTNER_API_URL"]
token = os.environ["PARTNER_API_TOKEN"]
if not proxy_url or not endpoint or not token:
    raise RuntimeError("Required tool configuration is empty")

parsed = urlsplit(endpoint)
if parsed.scheme != "https" or not parsed.hostname or parsed.username or parsed.password:
    raise RuntimeError("Use a configured HTTPS endpoint without URL credentials")

partner_session = requests.Session()
partner_session.trust_env = False
partner_session.proxies.update({"http": proxy_url, "https": proxy_url})
partner_session.headers.update({"Authorization": f"Bearer {token}"})

def call_partner_api():
    with partner_session.get(endpoint, timeout=(5, 20), allow_redirects=False) as response:
        if not 200 <= response.status_code < 300:
            raise RuntimeError(f"Partner API returned HTTP {response.status_code}")
        return response.json()

trust_env=False makes this session's routing explicit instead of inheriting environment proxy settings. It also disables environment-derived configuration such as netrc authentication and CA-bundle overrides. Set any required private CA bundle explicitly on the session; do not disable TLS verification. Close the session when the worker shuts down.

Selective Routing Is a Client Configuration

Only calls using the configured agent or session take this route. A framework's built-in tool, another SDK, a subprocess, or an unrelated client may use a different connection path. Setting QUOTAGUARDSTATIC_URL does not configure those clients by itself.

For Python requests you explicitly intend to leave unproxied, use a separate session with no proxy mapping and trust_env=False. Passing proxies=None is not a guarantee of direct access because Requests can still inherit environmental proxy settings. Do not reuse the partner session's credentials for unrelated destinations.

SFTP and native database tools use different protocols. Use a compatible SOCKS5 client or QGTunnel on a runtime you control. An HTTP-client example does not automatically route raw TCP tools or create private-network access.

Verify the Route Without Logging Secrets

Make a separate request to https://ip.quotaguard.com using the same proxy agent or an equivalent proxy-only session. Do not send the partner's API token to the IP-check service. The returned address should match either assigned QuotaGuard IP, and the destination must allowlist both.

Then verify the real tool call in the destination's logs. The echo check proves its own request, not every connection in the agent workflow. Keep request IDs and tool-level audit logs in your application; a shared exit address does not identify which individual agent acted.

Never log the complete proxy URL, authorization headers, prompts containing secrets, or unredacted error objects. Keep reusable credentials out of model context. If untrusted generated code runs in the same process or environment, environment variables do not hide those credentials from it. Use a separately controlled tool service or other enforced credential boundary where needed.

Shared or Dedicated Source Addresses

Standard QuotaGuard plans provide stable pairs on shared infrastructure. Choose Enterprise dedicated addresses and proxy resources when a client requires an identity used only by your organization. Dedicated infrastructure separates your source addresses from other QuotaGuard customers; it does not make a stolen credential harmless or enforce per-agent permissions.

Keep narrowly scoped destination credentials, least-privilege tool permissions, rotation, and application logging. QuotaGuard manages the egress service; your application defines which actions and destinations each tool is authorized to use.

Static, Shield, and Regional Placement

QuotaGuard Static starts at $19 per month. For outbound HTTPS, the payload stays encrypted to the destination and QuotaGuard does not decrypt it. Static's CONNECT request and proxy authentication use the standard unencrypted HTTP proxy protocol on the customer-to-proxy hop.

QuotaGuard Shield starts at $29 per month. It adds TLS protection to that hop. Choose Shield when your security review or approved regulated-data architecture requires it, using a compatible client and the Shield connection configuration. The Static examples above are not instructions to use the same URL unchanged for Shield.

Choose from 12 AWS regions at signup; contact support to change an existing subscription's region. Regional proxy placement is not a blanket guarantee about every transit path or where all account and operational data is stored. Review the documented data flow for your architecture.

Build the Tools. Let QuotaGuard Run the Exit.

Start with one protected connection, configure its real HTTP client, and give the destination a small stable pair to approve. You keep the tool logic and access controls; QuotaGuard handles the managed proxy infrastructure and its operations.

See the AI-agent integration overview, compare plans, or talk to engineering about your runtime and protected destination.

QuotaGuard Static IP Blog

Practical notes on routing cloud and AI traffic through Static IPs.

Reliability Engineered for the Modern Cloud

For over a decade, QuotaGuard has provided reliable, high-performance static IP and proxy solutions for cloud environments like Heroku, Kubernetes, and AWS.

Get the fixed identity and security your application needs today.