Salesforce Static IPs

Secure, Load-Balanced Static IP Addresses for Your AppExchange ISV Integrations.

Built for Salesforce's OAuth Refresh Token IP Allowlist Requirement.

The Trusted Foundation: Reliability, Speed, and Support

All QuotaGuard solutions are built on a decade of experience and a high-availability architecture designed to scale with your AppExchange ISV business.

Load Balanced Pair of Static IPs

Each subscription has a load balanced pair of static IP addresses. If one IP fails, traffic automatically routes through your second IP with health checks and automated failover, guaranteeing zero downtime and zero manual intervention.

Salesforce's Refresh Token IP Allowlist supports up to 128 ranges and 256 total IPs, so adding both QuotaGuard IPs is straightforward.

Ultra-Low Latency and Global Reach

You select what app region you want for ultra-low latency. Our proxies run on 10 AWS regions, ensuring your traffic stays fast regardless of where your ISV infrastructure is hosted.

Region is set at sign-up and can be changed any time via support.

Demonstrated Reliability and Scalability

QuotaGuard has maintained 99.98% uptime since 2013.

With over 67,300 customers served, we provide a solution that is trusted and proven to scale, including the high-volume refresh token redemption workloads typical of established AppExchange listings.

Digital shield with IP address 35.123.45.67 connected to HTTP and SOCKS5 proxies and cloud storage icons with encryption lock.

FAQs

Common questions about Salesforce Static IPs and QuotaGuard.

Does QuotaGuard satisfy all five May 11 OAuth security controls?

No.

QuotaGuard solves the IP Allowlist requirement, per Salesforce's current position.

The other four controls (PKCE, Refresh Token Rotation, 30-day Idle Timeout, and IP Monitoring) are application-layer changes you implement in your own code or via Salesforce Setup.

QuotaGuard handles the network-layer requirement only.

We recommend reading Salesforce's official documentation on PKCE and RTR alongside setting up your static IPs.

Does this work for legacy 1GP-packaged Connected Apps, or only External Client Apps?

Salesforce's Refresh Token IP Allowlist UI is documented for External Client Apps Manager only.

If your integration is still on a legacy 1GP-packaged Connected App, contact your Salesforce account team to confirm the IP registration path before configuring QuotaGuard.

The QuotaGuard side of the setup is the same in either case (a static IP pair is the prerequisite), but the Salesforce-side UI for adding the IPs to the allowlist is currently ECA-only.

Some ISVs are migrating to ECA via the full migration path or shipping a sidecar 2GP package containing only an ECA. Our support team can help you understand the QuotaGuard side once your Salesforce path is clear.

What about JWT Bearer flow integrations? Do I need a static IP?

Probably not.

JWT Bearer flow integrations don't issue refresh tokens, so the Refresh Token IP Allowlist requirement is structurally inapplicable.

If your entire Salesforce integration is JWT Bearer (server-to-server with no user-context refresh tokens), you don't need a static IP for May 11 2026 compliance.

If you're running a mixed flow architecture where some paths use authorization code with refresh tokens, those paths still need the static IP.

What about mobile apps?

Salesforce has indicated that the IP Allowlist requirement is not applicable to public-facing mobile applications, since mobile clients connect from arbitrary consumer IPs.

QuotaGuard's static IP solution is for ISV server-to-server integrations, not mobile clients.

If your AppExchange listing is exclusively mobile, you don't need a static IP for May 11 compliance.

What is the difference between QuotaGuard Static and QuotaGuard Shield for Salesforce integrations?

QuotaGuard Static is the Builder's Choice for most Salesforce ISVs, focused on flexibility, speed, and securing standard OAuth API connections.

QuotaGuard Shield is the Buyer's Choice for ISVs handling regulated customer data through their AppExchange integration.

Shield offers end-to-end security with SSL Passthrough and an architecture designed specifically to meet strict HIPAA and PCI compliance requirements.

For the May 11 2026 IP allowlist requirement alone, Static is sufficient.

Shield becomes the right choice when your integration handles PHI, payment card data, or other regulated workloads.

How is QuotaGuard installed and configured for my Salesforce ISV integration?

Provision a load-balanced pair of static IPs from your QuotaGuard dashboard.

Add the QUOTAGUARDSTATIC_URL environment variable to your application infrastructure (Heroku, AWS Lambda, Render, Fly.io, or your platform of choice).

Configure your HTTP client or OAuth library to route requests to api.salesforce.com through the QuotaGuard proxy.

Then add both QuotaGuard IPs to your External Client App's Refresh Token IP Allowlist in Salesforce Setup.

Total setup time is roughly 2 minutes for the QuotaGuard configuration plus the time required to update the Salesforce allowlist.

Will my static IP addresses change if I upgrade or downgrade my plan?

No. Your static IP addresses stay the same through plan upgrades and downgrades.

This means you don't need to update your Salesforce IP allowlist or contact your customers when you change plans, which is critical during the May 11 mandate transition when stable infrastructure is at a premium.

What happens if my Salesforce integration exceeds its current traffic limits?

Our No Hard Stops policy means we keep processing your requests even if you exceed your plan's bandwidth limit.

Refresh token redemptions, OAuth flows, and customer-facing API traffic continue uninterrupted while we contact you about an upgrade.

AppExchange listings can have unpredictable traffic spikes during Security Review re-submissions, customer onboarding waves, or marketing pushes, and QuotaGuard absorbs them.

Is there a minimum commitment or cancellation fee?

No.

QuotaGuard plans are month-to-month with no minimum commitment or cancellation fees.

You can sign up, configure your IPs, and adjust your plan as your AppExchange listing scales.

Still have questions?

We don’t outsource Support to non-Engineers.

Reach out directly to the Engineers who built Shield to discuss your specific architecture, integration challenges, or compliance constraints here 👇

🚀 Ready to Get Started? Choose Your QuotaGuard Path

QuotaGuard STATIC

Why: You need a rock-solid, fixed IP for general API access, AI workflows, or standard third-party integrations.
Best For: Developers, startups, and general application connectivity.
Key Feature: SOCKS5 support for secure database access.
Sign Up for QG Static for Salesforce

QuotaGuard SHIELD

Why: You handle HIPAA, PCI, or sensitive PII data and require End-to-End Encryption (E2EE) for full compliance.
Best For: Regulated industries, financial services, and healthcare.
Key Feature: SSL Passthrough and key isolation.
Sign Up for QG Shield for Salesforce

Quotaguard has amazing customer service. Some of the best I've interacted with for B2B companies.

Whenever there are snags or setup issues, their support answers emails quickly and hops on zooms to debug with us.

Even with very little notice, they'll hop on zooms to debug. That is absolutely incredible.

Gary L.
CEO
Saas Ai Webflow Website Datalog TemplateSaas Ai Webflow Website Datalog Template

Before I found QuotaGuard, I had tried to use Fixie Socks.

However, I couldn't get it to work even after downloading a separate library that they recommend (fixie-wrench). So I was relieved to find QuotaGuard.

The QuotaGuard team clearly cares about their product and their customers. I enjoyed my interactions with them, and their product seems reliable so far.

Overall a solid choice for Heroku/MongoDB Atlas builds.

Gayle M.
Software Engineer- Health, Wellness and Fitness
Saas Ai Webflow Website Datalog TemplateSaas Ai Webflow Website Datalog Template

Reliability Engineered for the Modern Cloud

For over a decade, QuotaGuard has provided reliable, high-performance static IP and proxy solutions for cloud environments like Heroku, Kubernetes, and AWS.

Get the fixed identity and security your application needs today.