Skip to main content

Network & Firewall Requirements

The domains to allowlist so Mindsmith lessons and authoring work behind an enterprise egress allowlist or firewall - required first-party domains, video and voice, optional embeds, and the additional domains content authors need.

Written by Justin

Mindsmith loads lessons live from Mindsmith's servers. If your organization filters outbound web traffic, allow the domains below so lessons and authoring work end to end. All traffic is outbound-only over standard HTTPS (port 443), with secure WebSockets (wss://) on the same port for real-time features. No inbound connections are required.

Run a live check. Open app.mindsmith.ai/learner-network-check in a browser on an affected device and network. It tests the learner domains below from that device and shows exactly what is reachable and what is blocked. No Mindsmith login is required, so you can send the link straight to your network team. It does not test the author-only domains in the Content authors section.

Learners and authors have different needs. People taking lessons (learners) only need the first-party domains in the first section. People building lessons in the editor (authors) work in a broader surface and need the additional domains in the Content authors section - including fonts.googleapis.com and Google Fonts. If only your learners are behind the allowlist, you can skip the author section.

Learner access

Required for lessons to play. This is the list to send your network team for learner devices.

Required - first-party Mindsmith domains (allowlist both)

These are two separate registrable domains on purpose: user-uploaded content is isolated off the app's domain for security, so mindsmithusercontent.com is not under *.mindsmith.ai and must be listed explicitly.

Domain

Purpose

Protocol

*.mindsmith.ai

The Mindsmith app and APIs, first-party analytics and error tunnels (/ingest, /monitoring), and real-time collaboration.

HTTPS + WSS

mindsmithusercontent.com, eu.mindsmithusercontent.com

All learner content: images, audio narration, captions/VTT, code tiles, theme fonts, video source and poster, and scenario character images. Served from a separate domain for security isolation.

HTTPS

Required for now - the host learner content is moving from

This row is temporary. Learner content is in the middle of a move onto mindsmithusercontent.com. Until that move is complete, lessons still fetch images, audio, video, and fonts from Google Cloud Storage, so learners need this host as well. Once the move is finished it is no longer needed for the learner experience and this row will be removed from this article - allowlisting both now means nothing changes for you on the day we switch over, and the live check passes if either host is reachable.

Domain

Purpose

Protocol

storage.googleapis.com

The same learner content, on the host it is served from today. Temporary, until the move to mindsmithusercontent.com is complete.

HTTPS

Required if lessons use uploaded video

Domain

Purpose

Protocol

*.cloudflarestream.com

Adaptive (HLS) playback for uploaded video.

HTTPS

Conditional - voice conversation tiles

Required only if your lessons use voice conversation tiles, and only until your organization is moved to the Mindsmith enterprise voice relay (which keeps voice traffic within *.mindsmith.ai). Voice is not yet fully first-party.

Domain

Purpose

Protocol

generativelanguage.googleapis.com

Real-time voice conversation tiles.

HTTPS + WSS

Optional - third-party embeds

Only needed if your lessons embed these providers. Mindsmith cannot proxy them - the learner's browser connects to the provider directly. Skipping one only breaks that specific embed tile; everything else works.

Provider

Domains to allow

YouTube

www.youtube.com, www.youtube-nocookie.com, *.googlevideo.com

Vimeo

player.vimeo.com, *.vimeocdn.com, *.akamaized.net

Google Docs / Slides

docs.google.com

Content authors

If the people who create lessons also work behind the allowlist, add these on top of the learner list above. The editor is a broader surface, so it reaches more domains. This list may change as authoring features evolve, and the live check does not test it.

Domains

Purpose

storage.googleapis.com, fonts.googleapis.com, fonts.gstatic.com

Asset storage and Google Fonts. The first-party rewrite is learner-only, so the editor still loads these directly even after mindsmithusercontent.com is live - unlike the learner row above, these do not go away at cutover.

images.unsplash.com, media.giphy.com (media0.giphy.com through media4.giphy.com), i.ytimg.com

Image, GIF, and YouTube thumbnails in the editor media pickers.

widget.intercom.io, api-iam.intercom.io, api-iam.eu.intercom.io, api-iam.au.intercom.io, nexus-websocket-a.intercom.io, *.intercomcdn.com, static.intercomassets.com

In-app help and support chat.

fast.wistia.net, fast.wistia.com

The "Book a demo" video on the dashboard.

lh3.googleusercontent.com

Google profile avatars in the navigation, settings, and comments.

www.googletagmanager.com, www.google-analytics.com, region1.google-analytics.com, analytics.google.com, stats.g.doubleclick.net

Google Analytics (optional; excluded in the EU region, non-blocking if filtered).

Authors also reach the learner video and embed hosts above (Cloudflare Stream, YouTube, Vimeo, Google Docs) when editing those tile types, plus stream.mux.com, image.mux.com, and *.litix.io for Mux-backed video.

Guidance for your network team

  • Allowlist by domain name, not by IP address. Mindsmith serves content from cloud origins whose IPs change; the hostnames above are stable.

  • Adding these domains is safe to do in advance and is non-disruptive to your other traffic.

  • Keep any existing storage.googleapis.com and Google Fonts allowances if your authors work behind the allowlist - the learner list is the minimum for the learner experience, and authoring needs the additional domains above.

  • After making changes, confirm them from an affected device with the live check at app.mindsmith.ai/learner-network-check.

Troubleshooting

Start with the live check at app.mindsmith.ai/learner-network-check, run in a browser on the device and network that is having trouble. It names the specific learner domains that are blocked.

A lesson (or a SCORM/LMS launch) shows a grey or blank screen. This is almost always the network blocking the connection to Mindsmith, not a problem with the content. To confirm, open https://app.mindsmith.ai in a browser on the same device and network. If that page is also blank, the network is blocking Mindsmith - send this list to your network team.

The lesson loads but images, audio, or video are missing. This means the learner content host is being blocked - mindsmithusercontent.com, or storage.googleapis.com while the move above is still in progress. Allow both and reload.

Still stuck? Contact Mindsmith support from the in-app help menu.

Did this answer your question?