Skip to main content

Network & Firewall Requirements

The domains learners need, when Google Cloud Storage remains required during the transition, and the additional services content authors may need.

Written by Justin

Mindsmith loads lessons live from Mindsmith's servers. Learner devices need access to the three required services below. This article also explains when Google Cloud Storage remains required during the transition, services that Mindsmith contacts only when an author adds the corresponding feature to a lesson, and the additional services used while authoring.

All traffic is outbound-only over standard HTTPS (port 443), with secure WebSockets (WSS) on the same port for real-time features. No inbound connections are required.

Run a live check. Open app.mindsmith.ai/learner-network-check in a browser on an affected device and network. No Mindsmith login is required, so you can send the link straight to your network team.

Learners and authors have different needs. People taking lessons need the three services in the required section. Some organizations temporarily continue to receive learner assets from Google Cloud Storage. Keep any existing storage.googleapis.com allowance until Mindsmith confirms your organization has moved to mindsmithusercontent.com. YouTube, Vimeo, Generative Language, and Google Docs are used only when an author adds the corresponding feature. People building lessons in the editor need the additional domains in the Content authors section.

Learner access

The required list below applies to every learner device. The additional sections apply only during the hosting transition, to older lesson assets, or to features an author chose to add.

Required for all learners

Allow all three services below. For learner content, allow both mindsmithusercontent.com and *.mindsmithusercontent.com. Some network systems do not treat the wildcard as covering the root domain.

  • *.mindsmith.ai

    The Mindsmith app and APIs, first-party analytics and error tunnels, and real-time collaboration.

    Protocol: HTTPS and WSS

  • mindsmithusercontent.com

    *.mindsmithusercontent.com

    All learner content, including images, audio narration, captions, code tiles, theme fonts, video source and poster files, and scenario character images.

    Protocol: HTTPS

  • *.cloudflarestream.com

    Mindsmith-hosted video playback.

    Protocol: HTTPS

Required during transition and for legacy compatibility

Some organizations temporarily continue to receive current learner assets from Google Cloud Storage while their network allowlists are updated. For those organizations, blocking this domain can prevent current lessons from loading correctly. Keep it allowed until Mindsmith confirms that your organization has moved to mindsmithusercontent.com. It can also be required for older lesson content that references a legacy asset URL.

  • storage.googleapis.com

    Current learner assets for organizations still in transition, plus legacy asset URLs in older lessons.

    Protocol: HTTPS

Optional - author-initiated services

Mindsmith contacts the services below only when an author adds the corresponding feature to a lesson. They are not required for Mindsmith itself, and a blocked service does not affect lessons that do not use it.

  • generativelanguage.googleapis.com

    Voice conversation tiles.

    Protocol: HTTPS and WSS

YouTube, Vimeo, and Google Docs embeds

Mindsmith contacts a provider only when an author embeds content from it. The learner's browser connects to that provider directly. A blocked provider affects only its embed tile.

Content authors

If the people who create lessons also work behind the allowlist, add these domains on top of the learner list above. If only your learners are behind the allowlist, you can skip this section. The live network check does not test these author-only domains.

  • storage.googleapis.com

    fonts.googleapis.com

    fonts.gstatic.com

    Asset storage and Google Fonts used by the editor.

  • images.unsplash.com

    media.giphy.com and media0.giphy.com through media4.giphy.com

    i.ytimg.com

    Image, GIF, and YouTube thumbnails in the editor media pickers.

  • widget.intercom.io

    api-iam.intercom.io

    api-iam.eu.intercom.io

    api-iam.au.intercom.io

    nexus-websocket-a.intercom.io

    *.intercomcdn.com

    static.intercomassets.com

    In-app help and support chat.

  • fast.wistia.net

    fast.wistia.com

    The Book a demo video on the dashboard.

  • lh3.googleusercontent.com

    Google profile avatars in the navigation, settings, and comments.

  • region1.google-analytics.com

    analytics.google.com

    stats.g.doubleclick.net

    Optional Google Analytics services. These are excluded in the EU region and are non-blocking if filtered.

Authors also reach the learner video and embed hosts above when editing those tile types, plus stream.mux.com, image.mux.com, and *.litix.io for Mux-backed video.

Guidance for your network team

  • Allowlist by domain name, not by IP address. Mindsmith serves content from cloud origins whose IP addresses change.

  • Adding these domains is safe to do in advance and will not disrupt other traffic.

  • Keep any existing storage.googleapis.com allowance until Mindsmith confirms your organization no longer uses it. It also remains required for authors behind the allowlist and for older lesson content with legacy asset URLs.

  • After making changes, confirm them from an affected device and network with the live check at app.mindsmith.ai/learner-network-check.

Troubleshooting

Start with the live network check on the device and network that is having trouble. It names the learner services that are blocked.

A lesson or SCORM/LMS launch shows a grey or blank screen.

Run the learner network check on the same device and network. If it reports blocked Mindsmith domains, send the results and this article to your network team.

The lesson loads but images, audio, or video are missing.

Check mindsmithusercontent.com and *.mindsmithusercontent.com for images and audio, and *.cloudflarestream.com for Mindsmith-hosted video. If the live check marks storage.googleapis.com as required, or Mindsmith has not confirmed your organization has moved, check that domain as well. It can also be needed when only older lesson content is missing. Allow the blocked service and reload.

Still stuck? Contact Mindsmith support from the in-app help menu.

Did this answer your question?