LLMs.txt directory

Network access requirements

If your organization uses a firewall or Content Delivery Network (CDN) with domain-level access controls, allowlist the following domains when provisioning a new ThoughtSpot Cloud cluster or modifying an existing firewall configuration.

Critical domains

The following domains are required for ThoughtSpot to load. If any of these domains are blocked, ThoughtSpot will not function.

Domain Purpose

*.thoughtspot.cloud

ThoughtSpot application and APIs

*.thoughtspotartifacts.cloud

Static assets and build artifacts

*.thoughtspotlogin.cloud

Authentication and login flows

ok14static.oktacdn.com

Okta authentication assets

*.cloudfront.net

CDN-served ThoughtSpot resources

cdn.skypack.dev

JavaScript module delivery

cdn.jsdelivr.net

Open-source library assets

cdnjs.cloudflare.com

Open-source library assets

code.jquery.com

jQuery library

Optional domains

The following domains are required for specific ThoughtSpot features. Allowlist these domains if you use the corresponding features.

Domain Feature

cdn.mxpnl.com

Mixpanel product analytics

app.pendo.io

Pendo in-app guidance

cdn.pendo.io

Pendo in-app guidance

fonts.googleapis.com

Google Fonts

js.intercomcdn.com

Intercom in-app support

fast.wistia.com

Wistia embedded video content

Contact your network administrator to apply these allowlist rules. ThoughtSpot does not manage your organization’s firewall or CDN configuration.

Additional requirements for embedded deployments

If you are embedding ThoughtSpot in an external application, additional Content Security Policy (CSP) and Cross-Origin Resource Sharing (CORS) configuration is required beyond the firewall allowlist above. For more information, see Security settings.