Depending on your organization's security policy (firewall and proxy settings), you may need to configure permission settings for network access to use Dive. If Dive is not working properly, review the requirements below and submit a support request to your IT department.
Network basics
● Communication direction: Outbound traffic only from your internal device to the internet. Opening inbound ports is not required, and Episotech Ltd. does not initiate connections to your network.
● Encryption: All traffic uses TLS encryption.
● Protocol: Normal use requires only TCP (HTTP/HTTPS). Remote support (video calls) additionally requires UDP along with TCP.
Required domains
Domains marked as "Required" below are necessary to use Dive. All others are only required if you use the corresponding feature; you do not need to permit domains for features you do not use.
Required
| Domain | Reason |
|---|---|
| *.divedx.com | Multiple subdomains of divedx.com provide the Dive app, Video delivery, Help Center, Notifications, and other services. Wildcard registration is recommended. |
| *.googleapis.com | Media data (Video and Image), databases, and account authentication use Google Firebase API. |
| *.asia-southeast1.firebasedatabase.app | Real-time database synchronization uses Google Firebase. Automatic failover to other hosts within the domain requires wildcard registration. |
● If you cannot register a wildcard for *.divedx.com, register the following domains individually instead. If you register individually, you must submit a new request whenever Episotech Ltd. adds a subdomain. Individual registration often causes issues such as Help Center and Notifications failing to open; we recommend registering *.divedx.com whenever possible.
- app.divedx.com (Dive app)
- cdn.divedx.com (Video and Image delivery)
- help.divedx.com (Help Center and maintenance notifications. This is the destination for the Help Center and Notifications buttons at the top of the app.)
● If you cannot register a wildcard for *.googleapis.com, register the following domains individually instead:
- firebasestorage.googleapis.com (saving and playing Video and Image files)
- firestore.googleapis.com (database)
- www.googleapis.com (account authentication)
- identitytoolkit.googleapis.com (Log in and account management)
- securetoken.googleapis.com (maintaining Log in status)
- storage.googleapis.com (uploading Video and Image files)
● cdn.divedx.com is used for Video and Image delivery. Since September 29, 2026, all teams use this domain. If you have registered *.divedx.com, no individual configuration is needed. If you registered domains individually, please add cdn.divedx.com. Without access, images may not display. firebasestorage.googleapis.com (included in *.googleapis.com above) continues to be required.
Required by feature
| Feature in use | Domain | Reason |
|---|---|---|
| SSO (SAML or Microsoft Entra ID) | interactive-supporter-210107.firebaseapp.com | Used for single sign-on authentication handoff. |
| Microsoft 365 (SharePoint or OneDrive) integration | graph.microsoft.com | File list retrieval, Taken in, and write-back use Microsoft Graph API. |
| Google Drive integration | accounts.google.com apis.google.com docs.google.com www.googleapis.com docs.googleapis.com sheets.googleapis.com slides.googleapis.com |
Google account connection, file selection screen, Taken in, and SOP link addition use Google Drive and Google Docs, Sheets, and Slides APIs. If you register *.googleapis.com, the four googleapis.com domains do not require individual configuration. |
| Alignment AR SOP | arcore.googleapis.com visualpositioning.googleapis.com |
Google alignment technology APIs are used. |
| api.immersal.com | Spatial recognition (Immersal): The Dive app on site devices uses this for map retrieval and alignment. | |
| Remote support (video calls) | *.agora.io *.edge.agora.io *.sd-rtn.com *.edge.sd-rtn.com *.ap.sd-rtn.com *.statscollector.sd-rtn.com *.webrtc-cloud-proxy.sd-rtn.com *.rtnsvc.com *.edge.rtnsvc.com *.rtesvc.com *.edge.rtesvc.com |
Agora is used as the WebRTC service. See "Ports required for Remote support" below for required ports. |
| *.mapbox.com | Mapbox service is used for map display in Support Requests. If blocked, support staff cannot confirm the request location. |
● For SSO and Microsoft 365 integration, your organization's ID provider domain (such as login.microsoftonline.com or *.okta.com) and SharePoint domain (such as xx.sharepoint.com or xx-my.sharepoint.com) are typically already permitted in environments that already use those services. In most cases, no additional configuration is necessary, but check these domains if you experience connection issues.
● If you register *.googleapis.com above, arcore.googleapis.com and visualpositioning.googleapis.com for Alignment AR SOP do not require individual configuration.
● Note: Google Fonts (fonts.googleapis.com and fonts.gstatic.com) are used for font rendering on screens. If blocked, Dive continues to function normally, but the displayed font may change.
Email receipt
Dive sends emails from the address below. If you restrict email receipt, allow emails from this address:
- no-reply@episotech.com
Ports required for Remote support
This is only required if you use Remote support (video calls). Audio and Video primarily use UDP.
● Support side (Web browser on PC)
The provider publishes the following permitted targets:
TCP: 80, 443, 3433, 3478, 4700-5000, 5668, 5669, 6080, 6443, 8667, 9667, 30011-30013
UDP: 3478, 4700-5000
● Site side (Dive app on smartphone or smart glass)
The app connects to the same relay network as the support side (the domains listed above), so first request permission for the same settings as above.
However, the provider does not publish an allowlist method for the app-embedded SDK and directs customers with strict traffic restrictions to use the dedicated proxy method described below. For this reason, in environments with strict filtering, the permissions listed above may not be sufficient to establish connections.
● IP address restrictions: Relay node IP addresses are not fixed, so the provider recommends permitting by domain and port rather than by IP address.
If UDP cannot be permitted
The provider offers a proxy method for environments with strict traffic restrictions, restricting communication to TCP/TLS 443 only and using an IP address allowlist. However, the current Dive app does not enable this method, so individual validation is required for environments with complete UDP blocking, including feasibility assessment.
Additional items to review
If Remote support fails to connect, the cause may be one of the following:
● Outbound UDP communication is completely blocked
● All traffic is forced through a proxy
● TLS inspection (SSL decryption) includes the domains listed above
Updated 2026/09/24: Reorganized to recommend *.divedx.com registration. Added help.divedx.com to the individual registration list. Added email sender address.
Updated 2026/09/22: Added cdn.divedx.com for Video and Image delivery
Updated 2026/08/31: Added Microsoft 365 (SharePoint or OneDrive) integration, ID provider for SSO, Spatial recognition (Immersal), and Google Fonts. Reorganized the table into "Required" and "By feature" and recommend *.googleapis.com registration.
Updated 2026/07/31: Updated Remote support (video calls) domains and ports to the latest provider official information. Added Cloud Run, SSO, and map items
Updated 2026/04/25: Added firestore.googleapis.com