Allowlist your gateway IP in Atlassian Cloud
Atlassian's IP allowlists restrict who can open Jira issues and projects, Confluence spaces, Jira Service Management portals and a few other products, by public IP. It needs a Premium plan (Jira, JSM, Confluence, Compass) or Enterprise (Atlassian Analytics, Focus). With a Reach gateway IP, the allowlist is one entry per region instead of every home connection your team uses.
Create the allowlist
- Go to admin.atlassian.com → Security → Device Security → IP allowlists.
- IP allowlist (create), give it a name, and add the gateway IP in CIDR form
(
203.0.113.10/32). Up to 500 addresses or ranges per product. - Choose the products it applies to and save.
Route Atlassian through Reach first
Add atlassian.net (your site, e.g. yourcompany.atlassian.net), atlassian.com,
atl-paas.net and bitbucket.org if you use it to your organisation's routing policy,
so every member's browser exits via the gateway before the allowlist is enforced.
What it covers
Web access and API calls to the selected products. Mobile apps go through the same check — members on phones need the Reach Android/iOS app routing your Atlassian domain, or they will be denied.
Common questions
We're on Standard — is there any IP control?
No. IP allowlisting starts at Premium. Consider SAML SSO with an identity provider that supports IP conditions (e.g. Entra Conditional Access — see Allowlist: Microsoft 365) as an alternative.
Does the allowlist apply to Bitbucket?
Bitbucket Cloud has its own IP allowlisting on its Premium plan; it isn't covered by the Jira/Confluence list. Add the same gateway IP there.
What about integrations and webhooks from other SaaS?
Inbound integrations calling the Atlassian API from their own servers are blocked unless their IPs are on the list. Add the vendor's published ranges alongside the gateway IP.