Webinar: Better Agents, Easier than Ever — Thursday, June 18th at 9am PT / 12pm ET. Register Now
Version 2.5
Network endpoints

Network endpoints

A self-hosted Sema4.ai deployment communicates with a small set of Sema4.ai services over outbound HTTPS (port 443) — for licensing, image and update distribution, and a few managed services. Allow egress from your environment to the hostnames below.

These are the Sema4.ai endpoints only. Your deployment also needs egress to the services you connect it to — LLM providers, MCP servers, and databases. See Add networking rules.

Required endpoints

EndpointPurpose
get.sema4.aiEnterprise Portal — licensing, and install/update instructions.
proxy.sema4.aiContainer image distribution — pulling the application images.
registry.sema4.aiHelm chart registry — pulling and upgrading the application Helm chart (EKS/AKS).
app-updates.sema4.aiApplication update service — release availability and update delivery.
backend.sema4.aiLicense validation, issue/support report uploads, and Document Intelligence.

Optional endpoints

These are only needed when the corresponding capability is enabled for your deployment:

EndpointPurpose
llm.backend.sema4.aiSema4.ai-managed LLM proxy — only required if Sema4.ai provides a managed LLM endpoint for your deployment.
dx.sema4.aiProduct usage telemetry.

Unrestricted outbound HTTPS is the simplest configuration and what we recommend for most deployments. If your environment requires an explicit allow-list, the hosts above are the Sema4.ai destinations to include.