Which are the domains used by Kompass for allowlisting?
If your IT team needs to permit only the minimum necessary URLs for Kompass to work, this article lists every domain Kompass uses, grouped by purpose. Share it with whoever manages your network or firewall rules.
Application
The Kompass application itself is always served from a single domain:
| Purpose | Domain |
|---|---|
| Kompass application | (customer's domain).kompassbms.com |
This is the only domain required to use Kompass day to day.
Kompass sends email from the following domains. Allow these so that notifications, and replies from our team, reach your inbox and aren't blocked or filtered:
| Purpose | Domain |
|---|---|
| Emails from the Kompass team | kompassbms.com |
| Automated Kompass notifications | notify.eu.kompassbms.com |
| Support tickets | helpscout.net |
Documentation & support
These are optional, they're helpful resources, but Kompass will run without them:
| Purpose | Domain |
|---|---|
| Support / knowledge base | support.kompassbms.com |
| Feature requests | feedback.kompassbms.com |
A note on the /api/docs/ endpoint
The /api/docs/ endpoint is not required for normal day-to-day operation. It provides developer-facing documentation of the API and is used only when building against or exploring the Kompass API.
If your security team would prefer not to permit it, that's completely fine, it can be left off your allowlist with no impact on using Kompass.
If your IT team needs anything further, contact us at [email protected] and we'll be glad to help.