Skip to main content

Using GitHub IP allow lists with CircleCI OAuth and the GitHub App

Configuration of GitHub IP allow lists with CircleCI

Summary

If your GitHub organization (or enterprise) enables an IP allow list, CircleCI can only talk to that org from IPs that are allowed. The CircleCI GitHub App can automatically add its own IP ranges to the allow list, but those ranges apply only to traffic from the GitHub App installation. They do not cover classic GitHub OAuth traffic from CircleCI core services.

If your organizations is uses an OAuth connection (alone or alongside the GitHub App) must manually add CircleCI’s core service IP addresses to the allow list, even if they already appear on the allow list as "Managed by the CircleCI App GitHub App".

Symptoms

If your organization is connected over GitHub OAuth and if you do not manually add these IP addresses CircleCI will be unable to contact GitHub over OAuth which needed for many things, including permissions management, repository/project listing, configuration management. You may encounter the following when this happens:

  • The organization does not load in the CircleCI UI, or you are redirected away from plan / org settings

  • API or UI errors such as “Organization not found, or user does not have access”

  • OAuth authorization for the org looks healthy in GitHub (for example a green check on the authorized application), but CircleCI still cannot access the org.

  • GitHub membership is correct (the user is an org member or Owner), but CircleCI behaves as if you have no access.

After access is restored, previously followed projects may show Set up until they are followed again.

How GitHub IP allow lists interact with CircleCI

Integration

Whose IP reaches GitHub?

How it gets onto the allow list

GitHub App

IPs used by the CircleCI GitHub App installation, which may include IP addresses from the core service list.

Added automatically as “Managed by the CircleCI App GitHub App” when Enable IP allow list configuration for installed GitHub Apps is turned on

GitHub OAuth

CircleCI core service egress IPs (user-token API calls for membership, org access, Plan UI, and similar)

Must be added manually. App-managed entries do not cover this path

Adding IP addresses to the allow list

For GitHub OAuth, the core services IP list is published here. These can be added in GitHub using the following:

  1. GitHub → Org Settings → Security → Authentication security → IP allow list

  2. Add IP / CIDR → save → ensure the entry is enabled

  3. Enable the allow list itself if it isn’t already

For GitHub App installations, as stated above, these will be added automatically as long as the "Enable IP allow list configuration for GitHub Apps" is enabled.

You will need to have the Owner role for your organization or enterprise in order to do this. After adding these new IP addresses please Refresh permissions.

Additional content

Did this answer your question?