This article is for the IT and network team. It lists what the Windows app, the Chrome extension, the helpdesk panels and the admin portal need.
Three rules
-
Allow by host name, on TCP 443. All traffic is HTTPS or secure WebSocket (
wss). Taiwa and the translation providers do not publish fixed IP addresses, so a rule by IP address will break. - The one exception is WebRTC. A call on OpenAI sends its audio over outbound UDP. See WebRTC and UDP.
- All traffic is outbound. No product needs an inbound rule.
Taiwa
| Host | Port | Protocol | Used by | What for |
|---|---|---|---|---|
api.taiwa.cx |
443 | HTTPS | Windows app, extension, browser | Sign-in. The start, the heartbeat and the end of each translated call. Diagnostics. Message translation. |
app.taiwa.cx |
443 | HTTPS | Browser | The admin portal, and the sign-in page of the Windows app. |
taiwa.cx |
443 | HTTPS | Browser | The "get the extension" link in the helpdesk panels. |
updates.taiwa.cx |
443 | HTTPS | Windows app | The update feed and the installer, about 115 MB. |
127.0.0.1 |
A free local port | HTTP | Windows app, browser | The sign-in of the Windows app returns to the app here. This traffic never leaves the computer. |
The sign-in page of the Windows app needs both app.taiwa.cx and api.taiwa.cx in the browser. A rule for the Windows app alone does not let an agent sign in.
*.taiwa.cx is a safe wildcard for your allowlist. The Windows app and the extension send a Taiwa credential only to taiwa.cx and its subdomains.
Translation providers
The call audio goes straight between the agent's computer and the translation provider. It does not go through Taiwa. At the start of each call, Taiwa tells the app or the extension which provider to use. Your organisation's settings in the admin portal select the provider.
Allow the rows for the providers that your organisation uses.
| Host | Port | Protocol | Provider |
|---|---|---|---|
api.deepl.com, *.deepl.com
|
443 | WebSocket (wss) | DeepL |
generativelanguage.googleapis.com |
443 | WebSocket (wss) | Google Gemini |
api.openai.com, *.api.openai.com
|
443 | HTTPS (the WebRTC offer) | OpenAI |
| OpenAI media servers (not published) | Chosen by OpenAI | UDP (WebRTC) | OpenAI |
Helpdesk pages
The extension works inside these pages. Your network probably allows them already. You need only the rows for the helpdesks that you use.
| Host | Port | What for |
|---|---|---|
*.my.connect.aws |
443 | Amazon Connect |
*.twilio.com |
443 | Twilio, including Zendesk Talk |
*.zendesk.com |
443 | Zendesk |
*.zdusercontent.com, static.zdassets.com
|
443 | Zendesk apps, including the Taiwa panel |
workspace.aircall.io |
443 | Aircall |
*.hubspot.com |
443 | HubSpot |
app.intercom.com, app.eu.intercom.com, app.au.intercom.com
|
443 | Intercom |
*.freshdesk.com, *.myfreshworks.com
|
443 | Freshdesk and Freshcaller |
The Taiwa panels talk to the extension inside the browser, not over the network.
Sign-in and billing
| Host | Port | Used by | What for |
|---|---|---|---|
| Your identity provider | 443 | Browser | Single sign-on. Taiwa has no fixed host here. |
checkout.stripe.com, billing.stripe.com, api.stripe.com, js.stripe.com, *.js.stripe.com, hooks.stripe.com, m.stripe.network, b.stripecdn.com, invoice.stripe.com, pay.stripe.com, hcaptcha.com, *.hcaptcha.com
|
443 | Browser | The payment pages that the Billing tab of the admin portal opens. Only administrators need these. |
If a payment page fails, allow stripe.com, *.stripe.com, *.stripe.network and *.stripecdn.com.
WebRTC and UDP
DeepL and Google Gemini use a WebSocket on TCP 443. Only a call on OpenAI sends its audio over WebRTC.
- Allow outbound UDP from the agent's computer to the provider's media servers, and allow the replies. The provider does not publish their addresses or ports. So this rule usually has to allow outbound UDP to any destination.
- An HTTP proxy cannot carry this traffic, and TLS inspection cannot see it.
- The symptom: the call starts, and after about 10 seconds the Windows app says "This network may block UDP traffic. Ask your IT team to allow outbound UDP for Taiwa."
Check the connection
In the Windows app, the Connection to Taiwa check on the Diagnostics tab says if the app can reach Taiwa, and if the translation provider accepts a test session. The call audio uses a separate connection to the provider, which that check does not test.