Network Requirements for Contented Desktop App

Last updated: July 21, 2026

If your organization uses a firewall or web proxy, you may need to allowlist the following domains for the Contented desktop app to function correctly. All connections use HTTPS or WSS (WebSocket Secure) on port 443.

Required Domains

Domain

Protocol

Port

Purpose

contentedai.com

HTTPS

443

Core application

mobile-prod-api.contentedai.com

HTTPS

443

API

aistudio.contentedai.com

HTTPS

443

Core application

download.contentedai.com

HTTPS

443

App updates and downloads

contented-knowledge-base.help.usepylon.com

HTTPS

443

In-app help and support

api.workos.com

HTTPS

443

Authentication

contented-sydney-private-prod.s3-accelerate.amazonaws.com

HTTPS

443

Recording upload (cloud storage)

3oov2p5y9b.execute-api.ap-southeast-2.amazonaws.com

WSS

443

Real-time events (WebSocket)

Notes for IT Administrators

  • All traffic uses TLS encryption on port 443. No additional ports need to be opened.

  • If your organization performs TLS inspection (SSL interception), the Contented app relies on the Windows OS trust store and is compatible with corporate proxy certificates installed via Group Policy.

  • The two amazonaws.com domains are Contented's own AWS infrastructure (cloud storage and real-time API), hosted in the ap-southeast-2 (Sydney) region.

  • IP-based allowlisting is not recommended, as cloud infrastructure IPs change. Domain-based rules are more reliable.