Network requirements

Table of Contents

This article is for the IT and network team. It lists what the Windows app, the Chrome extension, the helpdesk panels and the admin portal need.

Three rules

  1. Allow by host name, on TCP 443. All traffic is HTTPS or secure WebSocket (wss). Taiwa and the translation providers do not publish fixed IP addresses, so a rule by IP address will break.
  2. The one exception is WebRTC. A call on OpenAI sends its audio over outbound UDP. See WebRTC and UDP.
  3. All traffic is outbound. No product needs an inbound rule.

Taiwa

Host Port Protocol Used by What for
api.taiwa.cx 443 HTTPS Windows app, extension, browser Sign-in. The start, the heartbeat and the end of each translated call. Diagnostics. Message translation.
app.taiwa.cx 443 HTTPS Browser The admin portal, and the sign-in page of the Windows app.
taiwa.cx 443 HTTPS Browser The "get the extension" link in the helpdesk panels.
updates.taiwa.cx 443 HTTPS Windows app The update feed and the installer, about 115 MB.
127.0.0.1 A free local port HTTP Windows app, browser The sign-in of the Windows app returns to the app here. This traffic never leaves the computer.

The sign-in page of the Windows app needs both app.taiwa.cx and api.taiwa.cx in the browser. A rule for the Windows app alone does not let an agent sign in.

*.taiwa.cx is a safe wildcard for your allowlist. The Windows app and the extension send a Taiwa credential only to taiwa.cx and its subdomains.

Translation providers

The call audio goes straight between the agent's computer and the translation provider. It does not go through Taiwa. At the start of each call, Taiwa tells the app or the extension which provider to use. Your organisation's settings in the admin portal select the provider.

Allow the rows for the providers that your organisation uses.

Host Port Protocol Provider
api.deepl.com, *.deepl.com 443 WebSocket (wss) DeepL
generativelanguage.googleapis.com 443 WebSocket (wss) Google Gemini
api.openai.com, *.api.openai.com 443 HTTPS (the WebRTC offer) OpenAI
OpenAI media servers (not published) Chosen by OpenAI UDP (WebRTC) OpenAI

Helpdesk pages

The extension works inside these pages. Your network probably allows them already. You need only the rows for the helpdesks that you use.

Host Port What for
*.my.connect.aws 443 Amazon Connect
*.twilio.com 443 Twilio, including Zendesk Talk
*.zendesk.com 443 Zendesk
*.zdusercontent.com, static.zdassets.com 443 Zendesk apps, including the Taiwa panel
workspace.aircall.io 443 Aircall
*.hubspot.com 443 HubSpot
app.intercom.com, app.eu.intercom.com, app.au.intercom.com 443 Intercom
*.freshdesk.com, *.myfreshworks.com 443 Freshdesk and Freshcaller

The Taiwa panels talk to the extension inside the browser, not over the network.

Sign-in and billing

Host Port Used by What for
Your identity provider 443 Browser Single sign-on. Taiwa has no fixed host here.
checkout.stripe.com, billing.stripe.com, api.stripe.com, js.stripe.com, *.js.stripe.com, hooks.stripe.com, m.stripe.network, b.stripecdn.com, invoice.stripe.com, pay.stripe.com, hcaptcha.com, *.hcaptcha.com 443 Browser The payment pages that the Billing tab of the admin portal opens. Only administrators need these.

If a payment page fails, allow stripe.com, *.stripe.com, *.stripe.network and *.stripecdn.com.

WebRTC and UDP

DeepL and Google Gemini use a WebSocket on TCP 443. Only a call on OpenAI sends its audio over WebRTC.

  • Allow outbound UDP from the agent's computer to the provider's media servers, and allow the replies. The provider does not publish their addresses or ports. So this rule usually has to allow outbound UDP to any destination.
  • An HTTP proxy cannot carry this traffic, and TLS inspection cannot see it.
  • The symptom: the call starts, and after about 10 seconds the Windows app says "This network may block UDP traffic. Ask your IT team to allow outbound UDP for Taiwa."

Check the connection

In the Windows app, the Connection to Taiwa check on the Diagnostics tab says if the app can reach Taiwa, and if the translation provider accepts a test session. The call audio uses a separate connection to the provider, which that check does not test.

Was this helpful?