Skip to main content

Overview

Some Salesforce orgs restrict which IP addresses may log in or call the API, through Login IP Ranges on profiles, Trusted IP Ranges at org level, or IP restrictions enforced on a Connected App. Jam Assistant supports these orgs: every request it sends to Salesforce leaves from a fixed IP address, so your Salesforce administrator can allowlist it once. This routing is not optional and not configured per customer. All Salesforce traffic from Jam Assistant, for every customer and for production and sandbox orgs alike, including orgs reached through a My Domain login URL, always leaves from the same fixed address. You can allowlist it even if your org does not enforce IP restrictions today, so that enabling them later does not interrupt the integration.

Fixed IP address

When Salesforce asks for a range, enter the address as both the start and the end of the range. This address is stable. If Jam ever adds or replaces an address, we announce it on this page before the change takes effect. If you want to be told directly, email support@wejam.ai once you have allowlisted the address, so we know whom to notify.

What comes from this address

Everything Jam Assistant’s servers send to Salesforce, regardless of the channel a user is on (web chat, WhatsApp, phone or voice call):
  • Exchanging the OAuth authorization code for tokens when a user connects Salesforce in Customize → Integrations.
  • Refreshing access tokens and validating stored tokens.
  • Every REST API call made by the Salesforce tools: SOQL and SOSL queries, reading and writing records, describing objects and fields.
This applies equally to the Salesforce and Salesforce Sandbox providers and to orgs connected through an org-specific login URL.

What does not come from this address

  • The OAuth consent step. When a user connects Salesforce, the login and consent screens open in the user’s browser at login.salesforce.com, test.salesforce.com, or your My Domain. That login arrives from the user’s own network, not from Jam. Profiles with Login IP Ranges must allow the user’s network, exactly as they do for any browser login.
  • Other providers. Connections to HubSpot and to the email, calendar, and chat providers do not use the fixed address today. Contact support@wejam.ai if one of these providers restricts access by IP address.
  • Voice calls. The audio connection for voice calls runs between the user’s browser or phone and ElevenLabs, not between Jam and Salesforce. Its network requirements are covered in Call Connection Issues. CRM actions taken during a voice call still reach Salesforce from the fixed address above.

Allowlisting the address in Salesforce

These steps are for your Salesforce administrator. Which of them apply depends on how your org restricts access, so check all three.
1

Add a trusted IP range for the org

Go to Setup → Security → Network Access and click New. Enter the fixed address as both Start IP Address and End IP Address. Trusted IP Ranges remove the identity verification challenge for logins from that address. On their own they do not block other addresses.
2

Extend the Login IP Ranges on the profiles of connecting users

Go to Setup → Users → Profiles, open the profile of each user who connects Jam Assistant, and add the fixed address under Login IP Ranges. Login IP Ranges are a hard restriction: Salesforce refuses any login from outside the listed ranges, and OAuth token requests count as logins. If Enforce login IP ranges on every request is enabled in Session Settings, every API call is checked as well. The same profile also needs the ranges your users log in from, because the consent step comes from their browser.
3

Check the IP Relaxation policy on the Connected App

Go to Setup → Apps → Connected Apps → Manage Connected Apps → Jam Assistant and click Edit Policies. Under IP Relaxation, any option that enforces IP restrictions applies the profile Login IP Ranges to Jam Assistant’s server-side calls, so the fixed address must be present in them. Relax IP restrictions, with or without a second factor, exempts the app from those ranges.
4

Repeat the steps in your sandbox

A sandbox is a separate org with its own Network Access, profiles, and Connected App policies. Jam Assistant reaches sandbox orgs from the same fixed address.
To confirm the setup, ask a user to connect or reconnect Salesforce in Jam Assistant, then open Setup → Login History. The new row shows Application = Jam Assistant and the fixed address as Source IP. A row also appears each time Jam Assistant refreshes a token; ordinary API calls do not create one.

How the fixed address works

The fixed address belongs to an egress proxy that Jam operates in the European Union. Jam Assistant’s servers open encrypted connections to Salesforce through this proxy. The proxy forwards the encrypted bytes without decrypting them, so TLS stays end to end between Jam Assistant and Salesforce, and the proxy only ever sees the destination hostname. Allowlisting the address complements the Connected App’s OAuth controls, it does not replace them. Users still authorise Jam Assistant through OAuth, and Jam Assistant still acts within each user’s own Salesforce permissions, as described in the Salesforce Admin Guide.

Troubleshooting

The Connected App enforces IP restrictions and the fixed address is missing from the Login IP Ranges of the connecting user’s profile. Add the address to that profile, or set IP Relaxation on the Jam Assistant Connected App to Relax IP restrictions.
The login and consent screens run in the user’s browser from their own network. Login IP Ranges on their profile must include that network. The fixed Jam address does not cover this step.
A sandbox is a separate org. Repeat the allowlisting steps in the sandbox, including the Connected App installation described in Troubleshooting Salesforce Connection.

Last updated: September 2026