How can my IT department allow Tenor?

If your organization has strict network security, a little setup may be required before Tenor works smoothly. You may need to ask your IT team to "allowlist" (also called "whitelist") our application so it isn't blocked by corporate filters.

Allowlisting (also known as whitelisting) is the process of telling your organization’s security tools (like firewalls, secure browsers, or email gateways) that a specific service is trusted and should be allowed through.

If Tenor isn't allowlisted, users may see blocked pages, login errors, or audio conversations that fail to connect — especially in organizations using tools like Mimecast Secure Browser Isolation, Zscaler, or Cisco Umbrella.

A note for your security team: All Tenor connectivity is outbound-only from your network, encrypted with TLS/DTLS. Tenor never requires inbound firewall rules, open listening ports, VPNs, or software agents installed on your infrastructure.

Quick allowlist (sufficient for most organizations)

As a starting point, you can request the following domains to be whitelisted:

Domain Port/Protocol Purpose
*.tenorhq.com    TCP 443 (HTTPS + WSS) Tenor core application
*.livekit.cloud    TCP 443 (HTTPS + WSS) Realtime audio signaling (secure WebSocket)
*.turn.livekit.cloud    TCP 443 (TLS) TURN media relay, used when UDP isn't available
*.host.livekit.cloud    UDP 3478 TURN/UDP servers that assist connection setup

LiveKit is a core vendor powering our realtime audio conversation experiences.

Note: If your org uses a secure browser (e.g., Mimecast), you will also need to disable isolation or inspection for these domains to ensure full functionality.

Full allowlist

If issues persist after the quick allowlist, your filters may also be blocking supporting services. This is the complete list of domains Tenor uses:

Domain Port / Protocol Vendor / Purpose
*.tenorhq.com TCP 443 (HTTPS + WSS) Tenor — core application
*.livekit.cloud TCP 443 (HTTPS + WSS) LiveKit — realtime audio signaling
*.turn.livekit.cloud TCP 443 (TLS) LiveKit — TURN media relay
*.host.livekit.cloud UDP 3478 LiveKit — TURN/UDP connectivity assist
*.stytch.com TCP 443 Stytch — authentication / login
*.posthog.com TCP 443 PostHog — product analytics
*.vapi.ai TCP 443 (HTTPS + WSS) Vapi — legacy audio vendor (being phased out)
*.daily.co TCP 443 (HTTPS + WSS) Daily — legacy audio vendor (being phased out)
*.wss.daily.co TCP 443 (WSS) Daily — legacy WebSocket endpoints
d1w25pxpopehu7.cloudfront.net TCP 443 Tenor content delivery (images / media assets)
*.ingest.sentry.io TCP 443 Sentry — error monitoring

WebSocket note: Tenor and LiveKit rely on secure WebSocket (WSS) connections. Some security gateways allow HTTPS but block the WebSocket protocol as a category — please ensure WSS is permitted to *.tenorhq.com , *.livekit.cloud , and (for legacy customers) *.daily.co .

Realtime media ports (for strict firewalls)

Audio conversations use WebRTC. In addition to the domains above, live audio flows over dedicated media ports. All connections are outbound-only — return traffic is handled by your firewall's standard stateful connection tracking.

Choose whichever tier your security policy supports. Tenor works on all three, but lower tiers will negatively impact latency and quality.

Tier 1 — Direct UDP (best quality). Allow outbound UDP 50000–60000 and TCP 7881 to all hosts. By default, Tenor connects users to the nearest LiveKit media cluster worldwide, so these rules are scoped by port rather than destination.

Tier 1a — Destination-scoped. If your policy requires destination restrictions, scope the Tier 1 rules to LiveKit's static IP ranges: 143.223.88.0/21 , 161.115.160.0/19 , 153.57.128.0/18 . These ranges cover all LiveKit traffic routed through US, EU, Canada, India, and Japan. Traffic that routes outside these ranges (e.g., via a proxy or VPN egress in another region) automatically falls back to TURN, so calls still connect. If you deploy destination-scoped rules, let Tenor Support know — we can pin your traffic to a covered region so it always stays in-range on the best-quality path.

Tier 2 — TCP only. If UDP egress is prohibited, allow outbound TCP 7881 (destination-scoped per Tier 1a if required).

Tier 3 — No firewall changes. If none of the above is possible, Tenor automatically falls back to TURN over TLS on TCP 443 to *.turn.livekit.cloud  — the same port as ordinary web traffic. Conversations still work, but audio quality and latency may be impacted

For more information on realtime media allowlisting, see this documentation from our vendor LiveKit.

Secure browsers and SSL/TLS inspection

Some security products intercept encrypted traffic ("SSL inspection") or render pages in a remote container ("browser isolation"). Both can break Tenor even when all domains are allowlisted, because TLS interception disrupts secure WebSocket (WSS) connections and WebRTC's DTLS handshake.

Please ask your IT team to:

  • Bypass SSL/TLS inspection for *.tenorhq.com , *.livekit.cloud , and *.turn.livekit.cloud
  • Disable browser isolation (e.g., Mimecast Secure Browser Isolation) for *.tenorhq.com

These are scoped exceptions for specific trusted domains — a standard request for realtime audio/video applications.


IT Checklist

Share this checklist with your IT / Engineering / Infosec team:

  • Confirm which security filters are in place (e.g., Zscaler, Cisco Umbrella, Mimecast, proxy or DNS filtering)
  • Add the domains above to your allowlist, with the listed ports
  • Ensure WebSocket (WSS) connections are permitted to Tenor and LiveKit domains
  • Bypass SSL/TLS inspection and browser isolation for the domains listed above
  • For best audio quality, allow outbound UDP 50000–60000 and TCP 7881 (see media port tiers above)
  • Test login and an audio conversation after allowlisting

Need Help?

If your team still experiences access issues after allowlisting, reach out to Tenor Support (support@tenorhq.com) and we'll help troubleshoot — including running a connection test to pinpoint exactly which path is blocked.

Still need help? Contact Us Contact Us