Network · WAVE Anchor

WAVE Anchor — the published surface

IP addresses and egress policy for customer network and security teams. All data here is measured from live infrastructure — not planned or aspirational.

Inbound — Cloudflare anycast

All wave.online domains resolve through a Cloudflare anycast pair. These are the IPs your firewall rules should reference for inbound traffic from WAVE services.

IP addressesDomainNote
172.66.40.86 / 172.66.43.170wave.onlineCloudflare anycast — primary + secondary
172.66.40.86 / 172.66.43.170www.wave.onlineSame anycast pair
172.66.40.86 / 172.66.43.170api.wave.onlineSame anycast pair
172.66.40.86 / 172.66.43.170status.wave.onlineSame anycast pair
172.66.40.86 / 172.66.43.170gateway.wave.onlineSame anycast pair
172.66.40.86 / 172.66.43.170runtime.wave.onlineSame anycast pair
172.66.40.86 / 172.66.43.170review.wave.onlineSame anycast pair
172.66.40.86 / 172.66.43.170app.wave.onlineSame anycast pair

Inbound — Dedicated IPs

These services run on dedicated inbound IPs (not behind Cloudflare anycast). Allow-list these for service-specific integrations.

IP addressPurposeHost
37.16.9.159SRT media ingressFly dedicated
168.220.82.233bridge-recv-gridFly dedicated
137.66.2.38sftp-stripeFly dedicated

Outbound — Egress spine

WAVE's outbound egress is pinned to a single spine. If your infrastructure requires allow-listing WAVE-originated traffic, use these IPs.

What you get

CapabilityAvailability
Published surface contract + live machine-readable egress feed + 7-day change-notice policyFree — included for every WAVE customer
Static Egress: a dedicated set of pinned IPs for your webhooks, reserved per tenantEnterprise
Guaranteed Delivery: signed webhooks + pinned egress + delivery receiptsEnterprise
Private Interconnect: your traffic never touches the public internetEnterprise

Security guidance

Receipts & verification