Contented Desktop App for Enterprise: Deployment, Network Requirements & Updates

Last updated: August 24, 2026

A guide for IT administrators deploying and managing the Contented desktop app across managed devices.


Who this guide is for

This guide is for IT teams deploying Contented centrally rather than having users install it themselves. It applies if:

  • Your users can't install software on their own machines

  • You deploy applications centrally (Intune, SCCM, Group Policy, etc.)

  • A user has landed on a screen asking for an email and password to download the app. That is usually a sign they should be on the MSI path instead.


What the MSI installer is

The MSI installer is a packaged version of the Contented desktop app built for centralised, IT-managed deployment. It lets your team install and maintain Contented on managed machines without individual users downloading anything.

One thing to know upfront: there is currently no automatic updater. Updates are distributed as new MSI links and need to be deployed manually across machines.


Network requirements (allowlisting)

If your organisation uses a firewall or web proxy, allowlist the domains below for the app to function correctly. All connections use HTTPS or WSS (WebSocket Secure) on port 443.

Domain

Protocol

Port

Purpose

contentedai.com

HTTPS

443

Core application

mobile-prod-api.contentedai.com

HTTPS

443

API

aistudio.contentedai.com

HTTPS

443

Core application

download.contentedai.com

HTTPS

443

App updates and downloads

contented-knowledge-base.help.usepylon.com

HTTPS

443

In-app help and support

api.workos.com

HTTPS

443

Authentication

contented-sydney-private-prod.s3-accelerate.amazonaws.com

HTTPS

443

Recording upload (cloud storage)

3oov2p5y9b.execute-api.ap-southeast-2.amazonaws.com

WSS

443

Real-time events (WebSocket)

Notes for IT administrators

  • All traffic uses TLS encryption on port 443. No additional ports need to be opened.

  • If your organisation performs TLS inspection (SSL interception), the app relies on the Windows OS trust store and is compatible with corporate proxy certificates installed via Group Policy.

  • The two amazonaws.com domains are Contented's own AWS infrastructure (cloud storage and real-time API), hosted in the ap-southeast-2 (Sydney) region.

  • IP-based allowlisting is not recommended. Cloud infrastructure IPs change, so domain-based rules are more reliable.


Deployment

The MSI deploys like any standard Windows installer. Most teams push it through Intune, though SCCM and Group Policy work equally well.

Before rolling out to all machines:

  1. Confirm the domains above are allowlisted on your firewall or proxy.

  2. Test the install and login on one machine first.

  3. Confirm a test user can log in and upload a recording. Login and upload rely on different domains, so a successful login alone doesn't confirm uploads will work.


Updates

Updates are currently manual. There is no automatic updater yet. New versions reach you two ways:

  1. Self-serve changelog and download page. You can pull the latest MSI and read release notes at any time, so you can decide whether an update is worth deploying.

    COMING SOON

  2. Email notification. Your registered IT contact is emailed when a new version is available.

Cadence: because installs are manual, MSI updates are released less frequently than the standard app, roughly every month

Recommendation: We highly recommend keeping the app as up to date as possible for the best user experience.

We would love your feedback: how do you prefer to get MSI updates? Would you use an MSI auto-updater?


Troubleshooting

Symptom

Likely cause

Fix

Can't log in / can't stay logged in

Firewall or proxy blocking the auth domains

Allowlist api.workos.com and the core contentedai.com domains

Can't upload recordings

Firewall blocking cloud storage or the WebSocket

Allowlist the two amazonaws.com domains

Uploads suddenly failing after previously working

Token issue, often on an outdated build

Log out and back in. If it persists, update to the latest MSI

Login or upload works for some users but not others

Inconsistent proxy or VPN routing

Confirm the same allowlist rules apply to all affected users and any VPN split-tunnel config

If an issue isn't resolved by the above, get in touch with the domains and steps you've already tried and we'll work through it directly.


Getting the smoothest experience

The single biggest predictor of a smooth deployment is having one named IT contact who owns the Contented technical relationship. Someone who can be emailed or called directly, and looped in when something needs resolving.

If your Contented deployment is managed by an external IT provider, please let us know who our point of contact should be.