Skip to main content

Cademy Whitelist Domains

Give your IT team the Cademy website, sign-in, file and email domains to allow when access is blocked.

Written by Artur Binzaru

Use this article if Cademy is blocked or only partly loads on a work, school or other managed network. Send it to the person who manages your organisation's firewall, web filter or email security.

For your IT team
Allow outbound HTTPS traffic on port 443 to the website and file domains below. Allow secure WebSocket traffic (WSS) on port 443 to sockets.cademy.io.

Core Cademy domains

If your security system accepts wildcard entries, allow both:

  • cademy.io

  • *.cademy.io

The wildcard covers Cademy subdomains, including course provider sites such as provider-name.cademy.io. It does not always include the main cademy.io address, so add both entries.

If your security system requires individual entries, allow:

  • cademy.io for public pages, checkout, learner accounts and password sign-in

  • admin.cademy.io for the Admin Dashboard

  • api.cademy.io for sign-in and Cademy data

  • static.cademy.io for the files used to display Cademy pages

  • images.cademy.io for uploaded media and files

  • assets.cademy.io for Cademy files and assets

  • cademy-images-io.b-cdn.net for optimised images

  • cademy-assets-io.b-cdn.net for optimised assets

  • user-avatars.cademy.io for profile pictures

  • sockets.cademy.io for live Admin Dashboard notifications and Inbox updates. Allow WSS on port 443.

Learners may open a course on a course provider's own Cademy subdomain or custom web address. If you do not allow *.cademy.io, add the full course website address shown in the learner's browser. If the provider uses a custom domain, add that exact domain too.


Domains needed for particular features

Add these only when your organisation uses the related feature:

  • external-auth.cademy.co.uk for signing in with Google, Facebook or an organisation's single sign-on service

  • forum-attachments.cademy.io for files attached to course forum posts

  • cademy-scorm-files.com for SCORM course content

  • click.cademy.io for tracked links in emails sent through Cademy

  • help.cademy.io for the Cademy Help Centre

Direct uploads and private files
Cademy uses secure, time-limited Amazon S3 links when someone uploads a file or opens private course content, quiz attachments, certificates or exports. Allow:

  • *.s3.eu-west-1.amazonaws.com

If your organisation cannot allow this wildcard, ask the IT team to copy the exact blocked s3.eu-west-1.amazonaws.com hostname and send it to Cademy Support.

Videos uploaded to Cademy
Allow:

  • player.mediadelivery.net

  • iframe.mediadelivery.net

  • vz-0181db81-5c3.b-cdn.net

These domains are used by Cademy's current video player and video stream.

Some existing courses contain images or assets uploaded before Cademy moved from cademy.co.uk to cademy.io. If older course content has missing images, also allow:

  • images.cademy.co.uk

  • assets.cademy.co.uk

  • cademy-images.b-cdn.net

  • cademy-assets.b-cdn.net


Allow Cademy emails

For automatic emails sent by the Cademy platform, allow the sender domain:

  • system.cademy.io

A course provider can also send Cademy emails from its own verified domain. If one provider's emails are blocked, allow the sender domain shown in that email.

For messages sent directly by the Cademy team, including replies from Support, allow cademy.io or the exact sender address, such as support@cademy.io.

Important
system.cademy.io is an email sender domain. It is not a website and does not need to open in a browser.


External content and payment services

A course page can also contain services that are not hosted by Cademy, such as an embedded video, meeting link, payment provider or another website. These domains vary by course and are not included in the Cademy list above.

If Cademy opens but one video, payment option, meeting link or embedded item is blocked, ask your IT team for the blocked domain. Share it with the course provider or Cademy Support before changing the firewall again.


Test the change

  1. Use the same device and managed network where the problem happened.

  2. Open the exact Cademy page that was blocked.

  3. Check the affected action, such as signing in, opening an image, downloading a file, opening SCORM content or selecting a link in an email.

  4. If the problem continues, record the date and time, including the time zone.

    • the full page address

    • a screenshot showing the complete error

    • the blocked domain or reason reported by the firewall or web filter

    • the device, browser and network being used

    • which entries your IT team allowed


Frequently asked questions

Do I need to allow every feature-specific domain?
No. Allow the core domains, then add a feature-specific domain only when your organisation uses that feature.

Why are cademy.io and *.cademy.io separate?
Some security systems do not include the main domain when a wildcard is allowed. Adding both prevents the main website from remaining blocked.

Why does the sign-in list include a cademy.co.uk domain?
external-auth.cademy.co.uk is Cademy's hosted sign-in address for Google, Facebook and organisation single sign-on.

Does this list include Cademy Beta?
No. This article lists production domains. If Cademy has asked your organisation to test Beta, contact Cademy Support for the Beta domain list.

Why does the list include older cademy.co.uk image domains?
Some existing course content still uses those image addresses. They are only needed if images are missing from older content.

Did this answer your question?