Version 14+ Android Kiosk Whitelisting Guide
Last updated: August 8, 2026
What are the domains/IP addresses that I need to whitelist for my GRUBBRR device(s) to function?
The table below lists the essential whitelisting options for your GRUBBRR Android device operating on version 15.x of our Kiosk application.
Note: All whitelisted addresses use TCP protocols unless otherwise noted in the table.
Kiosk Whitelisting Requirements
|
URL |
IP Address(es) |
Port |
Purpose |
|
console.grubbrr.com |
See Note B |
443 |
Allows the kiosk to download data from and upload data to the GRUBBRR Console |
|
prod-grubbrr.identity.us.auth0.com |
104.19.167.1/20* |
443 |
GRUBBRR account / identity provider |
|
builds.grubbrr.net |
13.107.246.1/28* |
443 |
Allows the kiosk to download updated software versions from application storage servers. |
|
api.nge.grubbrr.com |
20.119.0.28 |
443 |
Enables real-time, cloud-based communication between the Kiosk and the Console |
|
stgngeprodeastus.blob.core.windows.net |
52.239.169.1/23* |
443 |
Microsoft Azure data storage |
|
api.vfipayna.com/ipchapi/rh.aspx |
199.71.106.52 199.71.106.58 |
443 |
Allows the Verifone Gateway to process orders |
|
*.sentry.io |
See Note B |
443 |
Collects Kiosk App Logs and manages general Error Tracking |
|
*.pusher.com *.pusherapp.com |
See Note B |
443 |
Allows the kiosk to receive notifications from the GRUBBRR Portal |
|
ik.imagekit.io |
See Note B |
443 |
Allows the kiosk to communicate with media storage servers. These host the kiosk screensavers, images, and other UI elements of the kiosk software. |
|
fonts.gstatic.com |
See Note B |
443 |
Gives the Kiosk access to Google Font Libraries |
|
eastus-8.in.applicationinsights.azure.com |
See Note B |
443 |
Gives the Kiosk access to Microsoft Azure App Insights telemetry |
|
Portal.grubbrr.com |
443 |
Allows the kiosk to download data from and upload data to the GRUBBRR Portal | |
|
pushy.me |
443 |
Allows the kiosk to receive notifications from the GRUBBRR Portal | |
|
13.248.224.0/24 |
443 |
Allows the kiosk to communicate with media storage servers. These host the kiosk screensavers, images, and other UI elements of the kiosk software. | |
|
*.amazonaws.com |
TCP: 443 (HTTPS), TCP: 8883 (MQTT) |
Allows the kiosk to download updated software versions from application storage servers. |
Remote Management Whitelisting Requirements (Elo View 3)
|
URL/IP Address |
Ports |
Purpose |
|
74.120.218.143 |
443 |
EloView uses Armor for secure and PCI-compliant cloud hosting. Armor’s Virtual Private Cloud is fully integrated with Elo’s Secure Private Cloud. |
|
104.16.170.243 |
443 |
EloView uses Cloudfare to store and deliver files. |
|
|
443 |
EloView Web Portal Access |
|
*teamviewer.com |
TCP/UDP 5938 TCP 443 TCP 80 |
Enables remote assistance through Teamviewer |
|
io.eloview.com https://cognito-identity.us-west-2.amazonaws.com/ https://cognito-idp.us-west-2.amazonaws.com/ |
443, 8883 |
Core requirements for EloView operations |
|
443, 8883 |
Token API / OTA updates / OS360 Warranty check - outgoing | |
|
443, 8883 |
Provisioning base URL - outgoing | |
|
443, 8883 |
MQTT Broker URL | |
|
443, 8883 |
Upload logs / OTA build and private content – outgoing/incoming | |
|
443, 8883 |
Content icons on devices | |
|
443, 8883 |
Oauth login on devices | |
|
123 |
Used for NTP traffic. |
Notes
Note A: You can whitelist via entries in the "Address" or "IPs" column; you do not need to do both
Note B: These dynamic IP address ranges are managed by their corresponding cloud service providers and are NOT guaranteed to remain unchanged. It is highly recommended to use Domain Name-based whitelisting on your firewall to resolve these URLs and permit access based on the corresponding dynamic IP addresses.