Summary
If your GitHub organization (or enterprise) enables an IP allow list, CircleCI can only talk to that org from IPs that are allowed. The CircleCI GitHub App can automatically add its own IP ranges to the allow list, but those ranges apply only to traffic from the GitHub App installation. They do not cover classic GitHub OAuth traffic from CircleCI core services.
If your organizations is uses an OAuth connection (alone or alongside the GitHub App) must manually add CircleCI’s core service IP addresses to the allow list, even if they already appear on the allow list as "Managed by the CircleCI App GitHub App".
Symptoms
If your organization is connected over GitHub OAuth and if you do not manually add these IP addresses CircleCI will be unable to contact GitHub over OAuth which needed for many things, including permissions management, repository/project listing, configuration management. You may encounter the following when this happens:
The organization does not load in the CircleCI UI, or you are redirected away from plan / org settings
API or UI errors such as “Organization not found, or user does not have access”
OAuth authorization for the org looks healthy in GitHub (for example a green check on the authorized application), but CircleCI still cannot access the org.
GitHub membership is correct (the user is an org member or Owner), but CircleCI behaves as if you have no access.
After access is restored, previously followed projects may show Set up until they are followed again.
How GitHub IP allow lists interact with CircleCI
Integration | Whose IP reaches GitHub? | How it gets onto the allow list |
GitHub App | IPs used by the CircleCI GitHub App installation, which may include IP addresses from the core service list. | Added automatically as “Managed by the CircleCI App GitHub App” when Enable IP allow list configuration for installed GitHub Apps is turned on |
GitHub OAuth | CircleCI core service egress IPs (user-token API calls for membership, org access, Plan UI, and similar) | Must be added manually. App-managed entries do not cover this path |
Adding IP addresses to the allow list
For GitHub OAuth, the core services IP list is published here. These can be added in GitHub using the following:
GitHub → Org Settings → Security → Authentication security → IP allow list
Add IP / CIDR → save → ensure the entry is enabled
Enable the allow list itself if it isn’t already
For GitHub App installations, as stated above, these will be added automatically as long as the "Enable IP allow list configuration for GitHub Apps" is enabled.
You will need to have the Owner role for your organization or enterprise in order to do this. After adding these new IP addresses please Refresh permissions.
