Network access requirements
If your organization uses a firewall or Content Delivery Network (CDN) with domain-level access controls, allowlist the following domains when provisioning a new ThoughtSpot Cloud cluster or modifying an existing firewall configuration.
Critical domains
The following domains are required for ThoughtSpot to load. If any of these domains are blocked, ThoughtSpot will not function.
| Domain | Purpose |
|---|---|
|
ThoughtSpot application and APIs |
|
Static assets and build artifacts |
|
Authentication and login flows |
|
Okta authentication assets |
|
CDN-served ThoughtSpot resources |
|
JavaScript module delivery |
|
Open-source library assets |
|
Open-source library assets |
|
jQuery library |
Optional domains
The following domains support third-party services that ThoughtSpot uses for product analytics, in-app guidance, customer support, and content delivery. Allowlist these domains to ensure these services load correctly within your ThoughtSpot instance.
| Domain | Feature |
|---|---|
|
Mixpanel product analytics |
|
Pendo in-app guidance |
|
Pendo in-app guidance |
|
Google Fonts |
|
Intercom in-app support |
|
Wistia embedded video content |
|
Contact your network administrator to apply these allowlist rules. ThoughtSpot does not manage your organization’s firewall or CDN configuration. |
Additional requirements for embedded deployments
If you are embedding ThoughtSpot in an external application, additional Content Security Policy (CSP) and Cross-Origin Resource Sharing (CORS) configuration is required beyond the firewall allowlist above. For more information, see Security settings.