Use this article if Cademy is blocked or only partly loads on a work, school or other managed network. Send it to the person who manages your organisation's firewall, web filter or email security. It lists the domains to add to their allow list, which some security systems call a whitelist.
The lists are the addresses that Cademy's own pages and emails use. Payment, video and other services from other companies load further addresses of their own, so this article does not list every address a browser contacts. The sections "Services from other companies" and "Test the change" explain how to find an address that is still blocked.
Allowing these domains only lets Cademy load. Each person still logs in with their own Cademy account.
For your IT team
Allow outbound HTTPS traffic on port 443 to the website and file domains below. Allow secure WebSocket traffic (WSS) on port 443 to sockets.cademy.io.
Check that the network is the cause
Before you contact your IT team, open the Cademy page that fails on a device and network that your organisation does not manage, for example a personal phone using mobile data.
If the page works there, your organisation's network or a security tool on the managed device is blocking part of Cademy. Send this article to your IT team, with the full address of the page and what happened when you opened it.
If the page fails in the same way there, your organisation's network is not the cause. For a login problem, follow Log In and Find Courses You Are Attending or Bookings You Made.
Core Cademy domains
These domains serve Cademy's main pages. Learners and people who book courses use the public pages. The staff of a course provider (the training company, school or trainer running the course) also use the Cademy admin dashboard to manage courses and bookings.
Cademy's own domain
A wildcard entry such as *.cademy.io covers every address that ends in .cademy.io. If your security system accepts wildcard entries, allow both:
cademy.io*.cademy.io
The wildcard covers Cademy subdomains, including course provider sites such as provider-name.cademy.io. Some security systems do not apply a wildcard to the main cademy.io address, so add both entries.
If your security system requires individual entries, allow:
cademy.iofor public pages, checkout, learner accounts and logging inthe course provider's own Cademy site, such as
provider-name.cademy.io. Use the full address shown in the learner's browser.admin.cademy.iofor the Cademy admin dashboardapi.cademy.iofor logging in and Cademy datastatic.cademy.iofor the files used to display Cademy pagesimages.cademy.iofor images and files that course providers uploadassets.cademy.iofor Cademy's own images, scripts and filesuser-avatars.cademy.io, a second address for profile picturessockets.cademy.iofor live notifications and Inbox updates in the Cademy admin dashboard. Allow WSS on port 443.
Image delivery addresses
Cademy delivers images and profile pictures through the bunny.net content delivery network. These addresses do not end in cademy.io, so *.cademy.io does not cover them. Add them as well, whether you allowed the wildcard or the individual entries:
cademy-images-io.b-cdn.netfor course images and other uploaded imagescademy-assets-io.b-cdn.netfor Cademy's own imagescademy-user-avatars.b-cdn.netfor profile pictures
Courses shown on a course provider's own website
A course provider can show its Cademy courses and booking pages inside its own website. If learners book through that website, allow its address as well. The embedded pages load from the Cademy domains in this section.
Domains needed for particular features
Add these only when your organisation uses the related feature. The entries that end in cademy.io are already covered if you allowed *.cademy.io.
external-auth.cademy.co.ukfor logging in with Google, Facebook or an organisation's single sign-on service. Also allow the login pages of the service you use, such as Google, Facebook or your organisation's own login service.forum-attachments.cademy.iofor files attached to course forum postscademy-scorm-files.comfor SCORM course content (e-learning packages in the SCORM format)click.cademy.iofor tracked links in emails sent through Cademyhelp.cademy.iofor the Cademy Help Centre
Direct uploads and private files
Cademy uses secure, time-limited links to Amazon S3, Amazon's file storage service, when someone uploads a file or opens a private file. Uploads include course images and videos, profile pictures, forum attachments, quiz attachments and files added to a form. Private files include protected course content, exports and certificates downloaded in bulk.
Course provider staff always need this entry, because the files they upload in the Cademy admin dashboard go through it. Allow:
*.s3.eu-west-1.amazonaws.com
Cademy uses several hostnames that end in s3.eu-west-1.amazonaws.com, for different types of file. If your organisation cannot allow the wildcard, ask your IT team to allow each exact hostname that the firewall or web filter reports as blocked while the person uploads or opens the file.
Videos uploaded to Cademy
Videos that a course provider uploads to Cademy play through the bunny.net video service. Allow:
player.mediadelivery.netfor the video playeriframe.mediadelivery.netandassets.mediadelivery.netfor the older video player. Add both if a video in older course content uses the older player.vz-0181db81-5c3.b-cdn.netfor the video stream and video preview images
Videos posted in a course forum stream from a separate address that ends in b-cdn.net.
If your security system accepts wildcard entries and your policy permits them, *.mediadelivery.net and *.b-cdn.net cover every address in this article that ends in mediadelivery.net or b-cdn.net, including the forum video address. Both domains belong to bunny.net and are shared with other websites that use it.
If a video still does not play, ask your IT team which address was blocked and allow it.
Older course content
Some older course content uses image addresses on cademy.co.uk. If images are missing from older content, also allow:
images.cademy.co.ukassets.cademy.co.ukcademy-images.b-cdn.netcademy-assets.b-cdn.net
Allow Cademy emails
For automatic emails sent by the Cademy platform, allow the sender domain:
system.cademy.io
A course provider can also send Cademy emails from its own verified domain. If one provider's emails are blocked, allow the sender domain shown in that email.
If the reply address of a Cademy email ends in system.cademy.io, your organisation must also be able to send email to that domain.
For messages sent directly by the Cademy team, including replies from Support, allow cademy.io or the exact sender address, such as support@cademy.io.
Important: The address system.cademy.io is an email domain. It is not a website and does not need to open in a browser.
Services from other companies
Some Cademy features use services run by other companies. Their domains are not in the Cademy lists above. Each entry below names the first address that Cademy loads from the service. The service then loads further addresses of its own, so use that company's published list of domains for the full set.
Stripe (
js.stripe.com) for card payments at checkout, when the course provider offers themStripe (
js.stripe.com) and Klarna's own pages for Klarna payments at checkout, when the course provider offers themPayPal (
www.paypal.com) for PayPal payments at checkout, when the course provider offers themGoogle reCAPTCHA (
www.google.com) for enquiry forms, waitlist forms, other forms that a course provider shares, and creating a course provider account. These forms cannot be sent while reCAPTCHA is blocked.Google Maps (
www.google.com) for the map of an in-person course locationGoogle Fonts (
fonts.googleapis.comandfonts.gstatic.com) for the fonts offered in Certificate Templates in the Cademy admin dashboardIntercom (
widget.intercom.io) for the Cademy support chat in the Cademy admin dashboard
Some courses show a stock photo from Unsplash when the course provider has not added an image. If those course images are missing, also allow images.unsplash.com.
Connecting an app under Apps in the Cademy admin dashboard, such as Stripe, Zoom, Google Calendar Sync or Outlook Calendar Sync, opens that service's own login page. The network must allow that page too.
A course page can also contain items that the course provider chose and that are hosted elsewhere, such as an embedded video, a meeting link or a link to another website. These domains vary by course.
If Cademy opens but one payment option, form, map, video, meeting link or embedded item is blocked, ask your IT team for the blocked domain. Share it with the course provider or Cademy Support, so they can confirm which service it belongs to before the firewall is changed again.
Test the change
After your IT team has allowed the domains, check that the problem is fixed.
Use the same device and managed network where the problem happened.
Open the exact Cademy page that was blocked.
Check the affected action, such as logging in, opening an image, downloading a file, opening SCORM content or selecting a link in an email.
If the problem continues, record the date and time, including the time zone.
Send support@cademy.io:
the full page address
a screenshot showing the complete error
the blocked domain or reason reported by the firewall or web filter
the device, browser and network being used
which entries your IT team allowed
To test the live connection to sockets.cademy.io, open Inbox in the Cademy admin dashboard on a computer. A green dot at the top of the Inbox means the connection is working. A red dot means it is not.
Frequently asked questions
Do I need to allow every feature-specific domain?
No. Allow the core domains, then add a feature-specific domain only when your organisation uses that feature.
Why are cademy.io and *.cademy.io separate?
Some security systems do not include the main domain when a wildcard is allowed. Adding both prevents the main website from remaining blocked.
Why does the list include external-auth.cademy.co.uk?
It is Cademy's hosted login address for Google, Facebook and organisation single sign-on. It is on cademy.co.uk, so *.cademy.io does not cover it.
Can we allow Cademy by IP address instead of by domain?
No. Cademy runs on Amazon Web Services and the bunny.net content delivery network, and the IP addresses they use change. Allow the domain names in this article.
Do we need to allow e.cademy.co.uk?
No. Cademy sends usage statistics to e.cademy.co.uk, and Cademy's features do not rely on it. The same applies to Google Analytics, Google Tag Manager or Facebook tracking that a course provider adds to its own pages.
Does this list include Cademy Beta?
No. This article lists production domains. If Cademy has asked your organisation to test Beta, contact Cademy Support for the Beta domain list.
Why does the list include older cademy.co.uk image domains?
Some existing course content still uses those image addresses. They are only needed if images are missing from older content.
