Add Anthropic’s egress range to your allowlist
Requests from Claude to your services originate from Anthropic’s network. To let them through, add Anthropic’s published egress range to the service’s allowlist:If your Google Cloud project uses VPC Service Controls, an IP-based access level doesn’t admit Claude’s queries through the BigQuery connection. See Allow the connection through a VPC Service Controls perimeter on the BigQuery page.
Internet reachability
In an Anthropic-hosted environment, every request from a channel’s sandbox to your service passes through Agent Proxy, which carries HTTP and HTTPS only. A service reachable only over another protocol, such as SSH or a database’s native wire protocol, can’t be connected; put an HTTP API in front of it instead.IP allowlist vs. allowed websites
The IP allowlist on your service and the allowed websites on a connection are opposite sides of the same boundary:Events and webhooks
Events from connected services, like GitHub activity, are delivered directly to Anthropic, so there is no inbound listener to configure on your side.Related resources
- Add connections: the allowed-websites setting (the other direction: what Claude is allowed to reach)
- Allow a host without a credential: how hosts become reachable from a channel, including allow-all egress
- How agent identity works: how credentials are injected at the network boundary
- Setup overview: back to the console flow once the allowlist is in place