Network access requirements
If your organization uses a firewall or Content Delivery Network (CDN) with domain-level access controls, allowlist the following domains when provisioning a new ThoughtSpot Cloud cluster or modifying an existing firewall configuration.
Critical domains
The following domains are required for ThoughtSpot to load. If any of these domains are blocked, ThoughtSpot will not function.
| Domain | Purpose |
|---|---|
|
ThoughtSpot application and APIs |
|
Static assets and build artifacts |
|
Authentication and login flows |
|
Okta authentication assets |
|
CDN-served ThoughtSpot resources |
|
JavaScript module delivery |
|
Open-source library assets |
|
Open-source library assets |
|
jQuery library |
Optional domains
The following domains are required for specific ThoughtSpot features. Allowlist these domains if you use the corresponding features.
| Domain | Feature |
|---|---|
|
Mixpanel product analytics |
|
Pendo in-app guidance |
|
Pendo in-app guidance |
|
Google Fonts |
|
Intercom in-app support |
|
Wistia embedded video content |
|
Contact your network administrator to apply these allowlist rules. ThoughtSpot does not manage your organization’s firewall or CDN configuration. |
Additional requirements for embedded deployments
If you are embedding ThoughtSpot in an external application, additional Content Security Policy (CSP) and Cross-Origin Resource Sharing (CORS) configuration is required beyond the firewall allowlist above. For more information, see Security settings.