> ## Documentation Index
> Fetch the complete documentation index at: https://docs.wejam.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Allowlisting Jam Assistant in Salesforce

> Add the fixed outbound IP address of Jam Assistant to your Salesforce IP restrictions so an IP-restricted org accepts its CRM calls.

## Overview

Some Salesforce orgs restrict which IP addresses may log in or call the API, through Login IP Ranges on profiles, Trusted IP Ranges at org level, or IP restrictions enforced on a Connected App. Jam Assistant supports these orgs: every request it sends to Salesforce leaves from a fixed IP address, so your Salesforce administrator can allowlist it once.

This routing is not optional and not configured per customer. All Salesforce traffic from Jam Assistant, for every customer and for production and sandbox orgs alike, including orgs reached through a My Domain login URL, always leaves from the same fixed address. You can allowlist it even if your org does not enforce IP restrictions today, so that enabling them later does not interrupt the integration.

## Fixed IP address

| IP address | Used for |
| - | - |
| `3.126.191.46` | All traffic from Jam Assistant to Salesforce, production and sandbox orgs |

When Salesforce asks for a range, enter the address as both the start and the end of the range.

This address is stable. If Jam ever adds or replaces an address, we announce it on this page before the change takes effect. If you want to be told directly, email [support@wejam.ai](mailto:support@wejam.ai) once you have allowlisted the address, so we know whom to notify.

## What comes from this address

Everything Jam Assistant's servers send to Salesforce, regardless of the channel a user is on (web chat, WhatsApp, phone or voice call):

* Exchanging the OAuth authorization code for tokens when a user connects Salesforce in **Customize → Integrations**.
* Refreshing access tokens and validating stored tokens.
* Every REST API call made by the Salesforce tools: SOQL and SOSL queries, reading and writing records, describing objects and fields.

This applies equally to the **Salesforce** and **Salesforce Sandbox** providers and to orgs connected through an org-specific login URL.

## What does not come from this address

* **The OAuth consent step.** When a user connects Salesforce, the login and consent screens open in the user's browser at `login.salesforce.com`, `test.salesforce.com`, or your My Domain. That login arrives from the user's own network, not from Jam. Profiles with Login IP Ranges must allow the user's network, exactly as they do for any browser login.
* **Other providers.** Connections to HubSpot and to the email, calendar, and chat providers do not use the fixed address today. Contact [support@wejam.ai](mailto:support@wejam.ai) if one of these providers restricts access by IP address.
* **Voice calls.** The audio connection for voice calls runs between the user's browser or phone and ElevenLabs, not between Jam and Salesforce. Its network requirements are covered in [Call Connection Issues](/external/assistant/call-connection-issues). CRM actions taken during a voice call still reach Salesforce from the fixed address above.

## Allowlisting the address in Salesforce

These steps are for your Salesforce administrator. Which of them apply depends on how your org restricts access, so check all three.

<Steps>
  <Step title="Add a trusted IP range for the org">
    Go to **Setup → Security → Network Access** and click **New**. Enter the
    fixed address as both **Start IP Address** and **End IP Address**. Trusted
    IP Ranges remove the identity verification challenge for logins from that
    address. On their own they do not block other addresses.
  </Step>

  <Step title="Extend the Login IP Ranges on the profiles of connecting users">
    Go to **Setup → Users → Profiles**, open the profile of each user who
    connects Jam Assistant, and add the fixed address under **Login IP Ranges**.
    Login IP Ranges are a hard restriction: Salesforce refuses any login from
    outside the listed ranges, and OAuth token requests count as logins. If
    **Enforce login IP ranges on every request** is enabled in **Session
    Settings**, every API call is checked as well. The same profile also needs
    the ranges your users log in from, because the consent step comes from
    their browser.
  </Step>

  <Step title="Check the IP Relaxation policy on the Connected App">
    Go to **Setup → Apps → Connected Apps → Manage Connected Apps → Jam
    Assistant** and click **Edit Policies**. Under **IP Relaxation**, any option
    that enforces IP restrictions applies the profile Login IP Ranges to Jam
    Assistant's server-side calls, so the fixed address must be present in
    them. **Relax IP restrictions**, with or without a second factor, exempts
    the app from those ranges.
  </Step>

  <Step title="Repeat the steps in your sandbox">
    A sandbox is a separate org with its own Network Access, profiles, and
    Connected App policies. Jam Assistant reaches sandbox orgs from the same
    fixed address.
  </Step>
</Steps>

<Check>
  To confirm the setup, ask a user to connect or reconnect Salesforce in Jam
  Assistant, then open **Setup → Login History**. The new row shows
  **Application = Jam Assistant** and the fixed address as **Source IP**. A row
  also appears each time Jam Assistant refreshes a token; ordinary API calls do
  not create one.
</Check>

## How the fixed address works

The fixed address belongs to an egress proxy that Jam operates in the European Union. Jam Assistant's servers open encrypted connections to Salesforce through this proxy. The proxy forwards the encrypted bytes without decrypting them, so TLS stays end to end between Jam Assistant and Salesforce, and the proxy only ever sees the destination hostname.

Allowlisting the address complements the Connected App's OAuth controls, it does not replace them. Users still authorise Jam Assistant through OAuth, and Jam Assistant still acts within each user's own Salesforce permissions, as described in the [Salesforce Admin Guide](/external/assistant/salesforce-admin-guide#understanding-the-two-permission-layers).

## Troubleshooting

<AccordionGroup>
  <Accordion title="Salesforce returns 'ip restricted' or the connection stops working after IP restrictions were enabled">
    The Connected App enforces IP restrictions and the fixed address is missing
    from the Login IP Ranges of the connecting user's profile. Add the address
    to that profile, or set **IP Relaxation** on the Jam Assistant Connected
    App to **Relax IP restrictions**.
  </Accordion>

  <Accordion title="Users cannot complete the Salesforce login when connecting">
    The login and consent screens run in the user's browser from their own
    network. Login IP Ranges on their profile must include that network. The
    fixed Jam address does not cover this step.
  </Accordion>

  <Accordion title="The connection works in production but fails in the sandbox">
    A sandbox is a separate org. Repeat the allowlisting steps in the sandbox,
    including the Connected App installation described in
    [Troubleshooting Salesforce Connection](/external/assistant/salesforce-troubleshooting).
  </Accordion>
</AccordionGroup>

## Related articles

* [Salesforce Admin Guide](/external/assistant/salesforce-admin-guide) - install the Connected App and manage its policies
* [Troubleshooting Salesforce Connection](/external/assistant/salesforce-troubleshooting) - OAuth errors and permission issues
* [Integrations](/external/assistant/integrations) - connect Salesforce and other providers
* [Call Connection Issues](/external/assistant/call-connection-issues) - network requirements for voice calls

***

*Last updated: September 2026*


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.