Version 14+ Android Kiosk Whitelisting Guide

Last updated: August 8, 2026

What are the domains/IP addresses that I need to whitelist for my GRUBBRR device(s) to function?

 

The table below lists the essential whitelisting options for your GRUBBRR Android device operating on version 15.x of our Kiosk application. 

Note: All whitelisted addresses use TCP protocols unless otherwise noted in the table. 

Kiosk Whitelisting Requirements

URL

IP Address(es)

Port

Purpose

console.grubbrr.com

See Note B

443

Allows the kiosk to download data from and upload data to the GRUBBRR Console

prod-grubbrr.identity.us.auth0.com

104.19.167.1/20*

443

GRUBBRR account / identity provider

builds.grubbrr.net

13.107.246.1/28*

443

Allows the kiosk to download updated software versions from application storage servers.

api.nge.grubbrr.com

20.119.0.28

443

Enables real-time, cloud-based communication between the Kiosk and the Console

stgngeprodeastus.blob.core.windows.net

52.239.169.1/23*

443

Microsoft Azure data storage

api.vfipayna.com/ipchapi/rh.aspx
api.vfipayna2.com/ipchapi/rh.aspx
vhq.connect.verifone.com

199.71.106.52

199.71.106.58

443

Allows the Verifone Gateway to process orders

*.sentry.io

See Note B

443

Collects Kiosk App Logs and manages general Error Tracking

*.pusher.com

*.pusherapp.com

See Note B

443

Allows the kiosk to receive notifications from the GRUBBRR Portal

ik.imagekit.io

See Note B

443

Allows the kiosk to communicate with media storage servers. These host the kiosk screensavers, images, and other UI elements of the kiosk software.

fonts.gstatic.com

See Note B

443

Gives the Kiosk access to Google Font Libraries

eastus-8.in.applicationinsights.azure.com

See Note B

443

Gives the Kiosk access to Microsoft Azure App Insights telemetry

Portal.grubbrr.com

443

Allows the kiosk to download data from and upload data to the GRUBBRR Portal

pushy.me

443

Allows the kiosk to receive notifications from the GRUBBRR Portal

13.248.224.0/24
13.248.225.0/24
13.248.226.0/24
13.248.227.0/24
13.248.228.0/24
13.248.229.0/24
13.248.230.0/24
13.248.231.0/24
13.248.232.0/24
13.248.233.0/24
18.34.0.0/19
18.34.232.0/21
2600:1f68:8000::/39
2600:1fa0:8000::/39
2600:1ff0:8000::/39
2600:1ff8:8000::/40
2600:1ff9:8000::/40
2600:1ffa:8000::/40
3.5.0.0/19
44.192.134.240/28
44.192.140.64/28
52.216.0.0/15
54.231.0.0/16
76.223.100.0/24
76.223.101.0/24
76.223.102.0/24
76.223.103.0/24
76.223.104.0/24
76.223.95.0/24
76.223.96.0/24
76.223.97.0/24
76.223.98.0/24
76.223.99.0/24

443

Allows the kiosk to communicate with media storage servers. These host the kiosk screensavers, images, and other UI elements of the kiosk software.

*.amazonaws.com

TCP: 443 (HTTPS), TCP: 8883 (MQTT)

Allows the kiosk to download updated software versions from application storage servers.

Remote Management Whitelisting Requirements (Elo View 3)

URL/IP Address

Ports

Purpose

74.120.218.143
74.120.218.144

443

EloView uses Armor for secure and PCI-compliant cloud hosting. Armor’s Virtual Private Cloud is fully integrated with Elo’s Secure Private Cloud.

104.16.170.243
104.16.171.243
2606:4700::6810:aaf3 (IPv6, if applicable)
2606:4700::6810:abf3 (IPv6, if applicable)

443

EloView uses Cloudfare to store and deliver files.



443 

EloView Web Portal Access

*teamviewer.com 

TCP/UDP 5938

TCP 443

TCP 80



Enables remote assistance through Teamviewer

http://eloview.com/

io.eloview.com
manage.eloview.com

https://cognito-identity.us-west-2.amazonaws.com/

https://cognito-idp.us-west-2.amazonaws.com/

https://polaris-promote-prod.s3.us-west-2.amazonaws.com/

https://polaris-scan-prod.s3.us-west-2.amazonaws.com/

443, 8883

Core requirements for EloView operations

https://secure-api.eloview.com/prod 

443, 8883

Token API / OTA updates / OS360 Warranty check - outgoing 

https://secure-provisioning.eloview.com/prod 

443, 8883

Provisioning base URL - outgoing 

https://secure-broker.eloview.com 

443, 8883

MQTT Broker URL

https://secure-logs.eloview.com/

443, 8883

Upload logs / OTA build and private content – outgoing/incoming

https://secure-content.eloview.com/

443, 8883

Content icons on devices

https://secure-auth.eloview.com/

443, 8883

Oauth login on devices

*.pool.ntp.org/

https://time.android.org/

123

Used for NTP traffic. 

Notes

Note A: You can whitelist via entries in the "Address" or "IPs" column; you do not need to do both

Note B: These dynamic IP address ranges are managed by their corresponding cloud service providers and are NOT guaranteed to remain unchanged. It is highly recommended to use Domain Name-based whitelisting on your firewall to resolve these URLs and permit access based on the corresponding dynamic IP addresses.