← All IT admin guides

Allowlisting URLs for Nurture

The domains a school web filter or firewall needs to allow so Nurture loads and runs on the school network, whichever products your teachers use.

School networks filter the web, and they should. But a filter that has never heard of Nurture can quietly break it: a tab in Teams or Canvas that stays blank, a Signal session that never loads for students, or a join screen that spins forever on student devices while working fine on staff Wi-Fi.

This page is for whoever manages your school’s web filter or firewall — Smoothwall, Linewize, Lightspeed, FortiGuard, or whatever your network runs. Which Nurture domains to allow depends on the region your school is hosted in. Allow the every-region list plus your region’s complete list below, on both staff and student network policies, and Nurture works everywhere on your network, including student devices.

Using wildcards? Nurture’s own domains all sit under gonurture.com, so a *.gonurture.com rule covers them in one entry. Each region’s list also includes a few third-party hosts — api.instantdb.com and the azurecontainerapps.io hosts that serve real-time data and storage for your region — that still need allowing individually.

All Nurture traffic is HTTPS on port 443 — there are no unusual ports to open. If your filter performs SSL inspection and Nurture loads but live sessions drop, exempting the Nurture domains from inspection is the first thing to try.

Domains to allow per region

Every region

4 domains
  • app.gonurture.comthe Nurture application
  • start.gonurture.comthe get-started flow for schools setting up
  • www.gonurture.comthis website and the tutorials teachers follow
  • gonurture.comthe apex domain

The lists below are the complete set of hosts Nurture Signal needs for each deployment. Find your region and allow the whole block — every entry, not just the ones that look new — on both staff and student policies. A school that is missing one entry sees exactly the same symptom as a school that is missing all of them.

🌐 Global (default)

6 domains
  • signal.gonurture.comNurture Signal
  • api.instantdb.comreal-time data for live sessions
  • api-signal.gonurture.comthe Signal API
  • s3proxy-signal.gonurture.comSignal storage proxy
  • tenant.gonurture.comtenant routing
  • *signal.gonurture.comwildcard covering every Signal host under gonurture.com

🇦🇺 Australia

11 domains
  • signal.gonurture.comNurture Signal
  • api.instantdb.comreal-time data for live sessions
  • api-signal.gonurture.comthe Signal API
  • s3proxy-signal.gonurture.comSignal storage proxy
  • tenant.gonurture.comtenant routing
  • *signal.gonurture.comwildcard covering every Signal host under gonurture.com
  • au.gonurture.comthe Nurture application (Australia)
  • instant.icypebble-39af03d3.australiaeast.azurecontainerapps.ioreal-time data, hosted in Australia East
  • au-api-signal.gonurture.comthe Signal API (Australia)
  • s3proxy.icypebble-39af03d3.australiaeast.azurecontainerapps.iostorage proxy, hosted in Australia East
  • au-s3proxy-signal.gonurture.comSignal storage proxy (Australia)

🇪🇺 Europe

11 domains
  • signal.gonurture.comNurture Signal
  • api.instantdb.comreal-time data for live sessions
  • api-signal.gonurture.comthe Signal API
  • s3proxy-signal.gonurture.comSignal storage proxy
  • tenant.gonurture.comtenant routing
  • *signal.gonurture.comwildcard covering every Signal host under gonurture.com
  • eu.gonurture.comthe Nurture application (Europe)
  • instant.mangobay-2e28f6d9.swedencentral.azurecontainerapps.ioreal-time data, hosted in Sweden Central
  • eu-api-signal.gonurture.comthe Signal API (Europe)
  • s3proxy.mangobay-2e28f6d9.swedencentral.azurecontainerapps.iostorage proxy, hosted in Sweden Central
  • eu-s3proxy-signal.gonurture.comSignal storage proxy (Europe)

If Nurture runs inside your own Microsoft tenant — an on-tenant deployment — some hosts are unique to your tenant and are not listed here. We send that list to your central IT team directly; write to us if you need it again.

Endpoints you likely already allow

Nurture signs people in with the account the school already runs, so its sign-in flow touches your identity provider’s endpoints, not new ones. Schools running Microsoft 365 already allow login.microsoftonline.com and Microsoft’s published endpoint list; schools on Canvas already allow their Canvas instance’s domains.

Tutorial videos on this site are hosted on YouTube, so they play only where the school network allows YouTube. Nothing in the product itself depends on it.

How to test

The quickest proof is the real path, on the filtered network, on a student device:

  1. Open app.gonurture.com in a browser on the school network — the sign-in page should load.
  2. Have a teacher start a Signal session and a student join it from a student device on the student network.
  3. Have the student submit a response and confirm the teacher sees it arrive live.
  4. If teachers launch Nurture from Teams or Canvas, open it from there too — the tab should load, not sit blank.

If staff Wi-Fi works and the student network does not, the difference is almost always a filtering policy applied only to student traffic.

Still blocked?

Write to hello@gonurture.com with the filtering product you use and what you see — a blank tab, a spinner, a block page — and we will pinpoint the entry your allowlist is missing.

Make feedback matter

Not sure what your filter is blocking?

Send us the symptom and the filtering product you run, and we will pinpoint the entry your allowlist needs.