

Replit
QuotaGuard gives selected Replit backend connections two stable outbound IPs without requiring a custom Enterprise contract or a proxy stack your team must operate. Save the connection URL as a Secret, configure the clients that need the route, and allowlist both assigned addresses at the destination.
- Self-service managed egress: QuotaGuard operates the proxy infrastructure, availability, health checks, failover, monitoring, and engineer support.
- Selective routing: Route only the API, partner, payment, or database connections that require a fixed identity. Adding a Secret stores the credential; each HTTP client or tunnel must still be configured.
- An honest native-option disclosure: Replit advertises static outbound IPs on its custom-priced Enterprise plan. Public documentation does not define deployment coverage, IP count, exclusivity, or routing behavior. Use it when platform-level networking bundled into Enterprise is the specific requirement.
- HTTP, HTTPS, and raw TCP: Configure supported HTTP clients with the QuotaGuard URL. Use SOCKS5/QGTunnel for PostgreSQL, MySQL, MongoDB, SQL Server, and other supported raw TCP connections.
- Portable identity: The two addresses belong to the QuotaGuard subscription rather than a Replit container, so the allowlist can stay stable through deployments and a later platform move.
- Static or Shield: Static is the normal starting point and does not decrypt HTTPS payloads passing through its blind CONNECT tunnel. Shield adds TLS on the customer-to-proxy hop when policy or an approved compliance architecture requires it.
Deployment note: Runtime egress applies to backend workloads such as Autoscale, Reserved VM, and Scheduled deployments. Static deployments can use secrets during a build but have no backend runtime after publication. Replit Agent full-stack applications use Autoscale or Reserved VM deployments.