Overview
Some Salesforce orgs restrict which IP addresses may log in or call the API, through Login IP Ranges on profiles, Trusted IP Ranges at org level, or IP restrictions enforced on a Connected App. Jam Assistant supports these orgs: every request it sends to Salesforce leaves from a fixed IP address, so your Salesforce administrator can allowlist it once. This routing is not optional and not configured per customer. All Salesforce traffic from Jam Assistant, for every customer and for production and sandbox orgs alike, including orgs reached through a My Domain login URL, always leaves from the same fixed address. You can allowlist it even if your org does not enforce IP restrictions today, so that enabling them later does not interrupt the integration.Fixed IP address
When Salesforce asks for a range, enter the address as both the start and the end of the range.
This address is stable. If Jam ever adds or replaces an address, we announce it on this page before the change takes effect. If you want to be told directly, email support@wejam.ai once you have allowlisted the address, so we know whom to notify.
What comes from this address
Everything Jam Assistant’s servers send to Salesforce, regardless of the channel a user is on (web chat, WhatsApp, phone or voice call):- Exchanging the OAuth authorization code for tokens when a user connects Salesforce in Customize → Integrations.
- Refreshing access tokens and validating stored tokens.
- Every REST API call made by the Salesforce tools: SOQL and SOSL queries, reading and writing records, describing objects and fields.
What does not come from this address
- The OAuth consent step. When a user connects Salesforce, the login and consent screens open in the user’s browser at
login.salesforce.com,test.salesforce.com, or your My Domain. That login arrives from the user’s own network, not from Jam. Profiles with Login IP Ranges must allow the user’s network, exactly as they do for any browser login. - Other providers. Connections to HubSpot and to the email, calendar, and chat providers do not use the fixed address today. Contact support@wejam.ai if one of these providers restricts access by IP address.
- Voice calls. The audio connection for voice calls runs between the user’s browser or phone and ElevenLabs, not between Jam and Salesforce. Its network requirements are covered in Call Connection Issues. CRM actions taken during a voice call still reach Salesforce from the fixed address above.
Allowlisting the address in Salesforce
These steps are for your Salesforce administrator. Which of them apply depends on how your org restricts access, so check all three.1
Add a trusted IP range for the org
Go to Setup → Security → Network Access and click New. Enter the
fixed address as both Start IP Address and End IP Address. Trusted
IP Ranges remove the identity verification challenge for logins from that
address. On their own they do not block other addresses.
2
Extend the Login IP Ranges on the profiles of connecting users
Go to Setup → Users → Profiles, open the profile of each user who
connects Jam Assistant, and add the fixed address under Login IP Ranges.
Login IP Ranges are a hard restriction: Salesforce refuses any login from
outside the listed ranges, and OAuth token requests count as logins. If
Enforce login IP ranges on every request is enabled in Session
Settings, every API call is checked as well. The same profile also needs
the ranges your users log in from, because the consent step comes from
their browser.
3
Check the IP Relaxation policy on the Connected App
Go to Setup → Apps → Connected Apps → Manage Connected Apps → Jam
Assistant and click Edit Policies. Under IP Relaxation, any option
that enforces IP restrictions applies the profile Login IP Ranges to Jam
Assistant’s server-side calls, so the fixed address must be present in
them. Relax IP restrictions, with or without a second factor, exempts
the app from those ranges.
4
Repeat the steps in your sandbox
A sandbox is a separate org with its own Network Access, profiles, and
Connected App policies. Jam Assistant reaches sandbox orgs from the same
fixed address.
To confirm the setup, ask a user to connect or reconnect Salesforce in Jam
Assistant, then open Setup → Login History. The new row shows
Application = Jam Assistant and the fixed address as Source IP. A row
also appears each time Jam Assistant refreshes a token; ordinary API calls do
not create one.
How the fixed address works
The fixed address belongs to an egress proxy that Jam operates in the European Union. Jam Assistant’s servers open encrypted connections to Salesforce through this proxy. The proxy forwards the encrypted bytes without decrypting them, so TLS stays end to end between Jam Assistant and Salesforce, and the proxy only ever sees the destination hostname. Allowlisting the address complements the Connected App’s OAuth controls, it does not replace them. Users still authorise Jam Assistant through OAuth, and Jam Assistant still acts within each user’s own Salesforce permissions, as described in the Salesforce Admin Guide.Troubleshooting
Salesforce returns 'ip restricted' or the connection stops working after IP restrictions were enabled
Salesforce returns 'ip restricted' or the connection stops working after IP restrictions were enabled
The Connected App enforces IP restrictions and the fixed address is missing
from the Login IP Ranges of the connecting user’s profile. Add the address
to that profile, or set IP Relaxation on the Jam Assistant Connected
App to Relax IP restrictions.
Users cannot complete the Salesforce login when connecting
Users cannot complete the Salesforce login when connecting
The login and consent screens run in the user’s browser from their own
network. Login IP Ranges on their profile must include that network. The
fixed Jam address does not cover this step.
The connection works in production but fails in the sandbox
The connection works in production but fails in the sandbox
A sandbox is a separate org. Repeat the allowlisting steps in the sandbox,
including the Connected App installation described in
Troubleshooting Salesforce Connection.
Related articles
- Salesforce Admin Guide - install the Connected App and manage its policies
- Troubleshooting Salesforce Connection - OAuth errors and permission issues
- Integrations - connect Salesforce and other providers
- Call Connection Issues - network requirements for voice calls
Last updated: September 2026

