Skip to content

Endpoints to allowlist

Every host Dockli talks to, why, and whether it's needed only for Spark. All connections are outbound HTTPS on 443 — configure your firewall or proxy to allow them.

Last updated: July 2026

Dockli reaches a small, fixed set of hosts. Every connection is outbound HTTPS on port 443 — there are no inbound connections and no other ports. This page lists every host so your firewall or web proxy team can allowlist exactly what’s needed. For performance and proxy guidance, see Performance and network.

Outbound HTTPS/443 only

Dockli makes only outbound TLS connections on port 443. It never opens inbound ports. localhost:5050 is used strictly on-device between Dockli’s components and never leaves the machine.

Minimum for Essential

These hosts are required for the core Dockli experience — sign-in, browsing Microsoft 365, editing metadata, updates and diagnostics. Essential needs only these.

HostPurposePlan
login.microsoftonline.comMicrosoft Entra ID sign-in and token acquisitionAll
graph.microsoft.comMicrosoft Graph — files, sites, metadata, version historyAll
*.sharepoint.com (your tenant hosts)SharePoint / OneDrive content for your tenantAll
portal.tinytugboat.comDiagnosticsAll
Dockli licensing host
(Azure App Service)
Per-seat entitlement and licensing checksAll
stgdocklireleases.blob.core.windows.netApplication updatesAll

Additional for Spark

These hosts are only used by Spark, for Ask Dockli’s AI and voice dictation. If you run Essential only, you don’t need to allowlist them.

HostPurposePlan
dockli-api-gateway.azure-api.netAzure OpenAI via API Management (APIM) — Ask Dockli chat, search, diffSpark only
eastus.api.cognitive.microsoft.comAzure Speech — voice dictationSpark only
*.stt.speech.microsoft.comAzure Speech speech-to-text — voice dictationSpark only

Complete host reference

HostPurposeSpark-only?
login.microsoftonline.comEntra ID sign-in / tokensNo
graph.microsoft.comMicrosoft Graph (files, sites, metadata)No
*.sharepoint.comYour tenant’s SharePoint / OneDrive contentNo
portal.tinytugboat.comDiagnosticsNo
Dockli licensing host (Azure App Service)Per-seat entitlement / licensingNo
stgdocklireleases.blob.core.windows.netApplication updatesNo
dockli-api-gateway.azure-api.netAzure OpenAI via APIM (Ask Dockli)Yes
eastus.api.cognitive.microsoft.comAzure Speech (dictation)Yes
*.stt.speech.microsoft.comAzure Speech speech-to-text (dictation)Yes

Your SharePoint hosts

*.sharepoint.com covers your tenant’s SharePoint and OneDrive hosts (for example contoso.sharepoint.com and contoso-my.sharepoint.com). Scope the wildcard to your own tenant hosts if your proxy supports it.

Don't block updates or licensing

Blocking stgdocklireleases.blob.core.windows.net stops Dockli receiving updates, and blocking the licensing host prevents entitlement checks. Keep both on the allowlist even for an Essential-only deployment.

Where to go next

Still stuck? Email support@dockli.io — a human replies within one business day. Or book a demo.