Skip to main content

Network details for GHE.com

Ensure client systems can access your resources on GHE.com.

To access your enterprise on GHE.com, client systems must:

  • Trust GitHub's SSH key fingerprints
  • Have access to GitHub's hostnames and IP addresses

GitHub's SSH key fingerprints

To find these details, use the /meta API endpoint for your instance. For example, using the GitHub CLI:

gh api /meta --hostname octocorp.ghe.com

For more information, see REST API endpoints for meta data.

Using SSH with GHE.com

To clone a repository using Git over SSH from SUBDOMAIN.ghe.com, where SUBDOMAIN is your enterprise's dedicated subdomain on GHE.com, use the SUBDOMAIN as the SSH username instead of git.

git clone SUBDOMAIN@SUBDOMAIN.ghe.com:OWNER/REPO.git

GitHub's hostnames

  • *.SUBDOMAIN.ghe.com, where SUBDOMAIN is your enterprise's dedicated subdomain on GHE.com
  • *.pages.SUBDOMAIN.ghe.com
  • *.actions.SUBDOMAIN.ghe.com
  • *.githubassets.com
  • *.githubusercontent.com
  • *.blob.core.windows.net. If you cannot allow access to wildcard domains, see Azure Blob Storage hostnames.
  • auth.ghe.com

Azure Blob Storage hostnames

If you cannot allow access to *.blob.core.windows.net, use the /meta API endpoint for your enterprise to retrieve the complete list of client-facing Azure Blob Storage hostnames. For example, using the GitHub CLI:

gh api /meta --hostname octocorp.ghe.com --jq '.domains.storage[]'

Allow access to every hostname returned in domains.storage. The list is specific to your enterprise and GitHub keeps it up to date as network requirements change.

For more information about the /meta endpoint, see REST API endpoints for meta data.

Note

If you stream audit logs to your own Azure Blob Storage destination, you must allow access to that destination separately.

GitHub's IP addresses

GitHub's IP address ranges for enterprises on GHE.com depend on your chosen region.

The EU

Ranges for egress trafficRanges for ingress traffic
108.143.221.96/28108.143.197.176/28
20.61.46.32/2820.123.213.96/28
20.224.62.160/2820.224.46.144/28
51.12.252.16/2820.240.194.240/28
74.241.131.48/2820.240.220.192/28
20.240.211.176/2820.240.211.208/28

Australia

Ranges for egress trafficRanges for ingress traffic
20.5.34.240/284.237.73.192/28
20.5.146.128/2820.5.226.112/28
68.218.155.16/2820.248.163.176/28

US

Ranges for egress trafficRanges for ingress traffic
20.221.76.128/2874.249.180.192/28
135.233.115.208/2848.214.149.96/28
20.118.27.192/28172.202.123.176/28

Japan

Ranges for egress trafficRanges for ingress traffic
74.226.88.192/2874.226.88.240/28
40.81.180.112/2840.81.176.224/28
4.190.169.192/284.190.169.240/28

GitHub Copilot

Most GitHub Copilot services require access to your enterprise's subdomain on GHE.com and its subdomains. For more information, see Copilot allowlist reference.

Supported regions for Azure private networking

GitHub deploys your runners in the same Azure region as the subnet you connect them to. Because of this, your subnet must be in one of the supported regions. If you use Azure private networking for GitHub-hosted runners, the supported Azure regions on GHE.com differ from those on GitHub.com.

Supported regions in the EU

Runner typeSupported regions
x64francecentral, swedencentral, germanywestcentral, northeurope
arm64francecentral, northeurope, germanywestcentral
GPUitalynorth, swedencentral

Supported regions in Australia

Runner typeSupported regions
x64australiaeast, australiacentral
arm64australiaeast, australiacentral
GPUaustraliaeast, australiacentral

Supported regions in the US

Runner typeSupported regions
x64centralus, eastus2, westus3
arm64centralus, eastus2, westus3
GPUcentralus, eastus2, westus3

Supported regions in Japan

Runner typeSupported regions
x64japaneast, japanwest
arm64japaneast, japanwest
GPUjapaneast

IP ranges for Azure private networking

EU

Actions IPs:

  • 74.241.192.231
  • 20.4.161.108
  • 74.241.204.117
  • 20.31.193.160

EU region:

  • 108.143.197.176/28
  • 108.143.197.160/28
  • 20.123.213.96/28
  • 20.123.214.144/28
  • 20.224.46.144/28
  • 20.224.46.160/28
  • 20.240.194.240/28
  • 20.240.194.224/28
  • 20.240.220.192/28
  • 20.240.220.176/28
  • 20.240.211.208/28
  • 20.240.211.224/28

Australia

Actions IPs:

  • 4.147.140.77
  • 20.53.114.78

Australia region:

  • 4.237.73.144/28
  • 4.237.73.192/28
  • 20.5.226.96/28
  • 20.5.226.112/28
  • 20.248.163.160/28
  • 20.248.163.176/28

Japan

Actions IPs:

  • 20.63.233.164
  • 172.192.153.164

Japan region:

  • 74.226.88.240/28
  • 74.226.88.224/28
  • 40.81.176.224/28
  • 40.81.178.160/28
  • 4.190.169.240/28
  • 4.190.170.0/28

Required for all regions

  • Storage service tag
  • Communication requirements for github.com
    • 192.30.252.0/22
    • 185.199.108.0/22
    • 140.82.112.0/20
    • 143.55.64.0/20
    • 20.201.28.151/32
    • 20.205.243.166/32
    • 20.87.245.0/32
    • 4.237.22.38/32
    • 20.207.73.82/32
    • 20.27.177.113/32
    • 20.200.245.247/32
    • 20.175.192.147/32
    • 20.233.83.145/32
    • 20.29.134.23/32
    • 20.199.39.232/32
    • 20.217.135.5/32
    • 4.225.11.198/32
    • 4.208.26.197/32
    • 20.26.156.215/32

Domains for Azure private networking

Required for all regions

  • *.<TENANT>.ghe.com
  • <TENANT>.ghe.com
  • github.com
  • *.githubusercontent.com
  • *.blob.core.windows.net. To allow access only to the hostnames used by your enterprise, see Azure Blob Storage hostnames.
  • *.web.core.windows.net

OAuth callback URL for connecting an Azure subscription for billing

When you connect or update an Azure subscription for billing, you must allow access to the following URL:

  • https://github.com/enterprises/oauth_callback

This URL is required during the OAuth authentication flow that occurs when:

  • Connecting an Azure subscription to your enterprise for the first time
  • Changing or updating an existing Azure subscription connection

Important

  • The URL must be allowed with all query parameters, for example https://github.com/enterprises/oauth_callback?code=...
  • After the Azure subscription is successfully connected and the subscription ID is stored, you can remove this URL from your allowlist
  • To change or update your Azure subscription, you must add the URL back to your allowlist

The OAuth flow works as follows:

  1. The user starts the connection process on SUBDOMAIN.ghe.com
  2. Azure redirects to https://github.com/enterprises/oauth_callback to complete the OAuth flow
  3. The system redirects back to SUBDOMAIN.ghe.com to finalize the connection

IP ranges for GitHub Enterprise Importer

If you're running a migration to your enterprise with GitHub Enterprise Importer, you may need to add certain ranges to an IP allow list. See Managing access for a migration between GitHub products.