What ports and URLs does Transfr need allowlisted?

The canonical list of ports, URLs, and protocols to allowlist for Transfr headsets and web tools. Print it straight from the page for your network team.

For: IT administrators and network teams

This is the canonical list of ports, URLs, and protocols Transfr needs allowlisted on your network. It's the same list for the Quest 2, Quest 3S, and Pico Neo 3. If headsets join your Wi-Fi but simulations won't load, a blocked endpoint is the usual cause — start with the connectivity test below.

Every other Transfr article that mentions these endpoints points here, so this page is the one to check for the current list.

🖨 Print this page, or save it as a PDF — or just press Ctrl+P (Cmd+P on a Mac). It comes out as a clean handout you can give or email to a network team: site navigation stripped, every address spelled out in full, and the addresses stay selectable text so they can be copied straight into a firewall rule. There is no separate file to download, so what you print always matches this page.

In this guide

Test your network connectivity

Before you change any firewall rules, run the test from a device on the same network the headsets will use: Test Your Network Connectivity.

What success looks like: every endpoint passes. Anything that fails is being blocked somewhere on your network — usually a firewall or a content filter — and that is the rule your network team needs to change.

Ports

Open 443 and 80 outbound. Allow the addresses below and prohibit access to anything else.

If you run an older legacy headset, check with Transfr Technical Support before you build the rule.

Headset endpoints

Every headset must be able to reach:

  • https://backend.transfrvr.com
  • https://func.transfrvr.com
  • https://functions.transfrvr.com/
  • https://vr-api.transfrvr.com/
  • https://xr-assets.transfrvr.com/
  • https://mqtt-proxy-server.tx-xr.com
  • https://shared-message-broker-prod.tx-xr.com
  • http://transfrvr-asset-bundles.s3.us-east-2.amazonaws.com/
  • http://o505023.ingest.sentry.io/
  • https://d2mejnog76nh2i.cloudfront.net/

Dashboard and Trek endpoints (web browser)

Two Transfr tools run in a web browser rather than in the headset: the Transfr Dashboard, where your staff manage classrooms and learners, and Transfr Trek, a career-exploration tool some learners use on a computer or Chromebook. Every site needs the Dashboard; add Trek if your learners use it. Those computers must also be able to reach:

  • *.transfrinc.com — including https://trek.transfrinc.com, https://dashboard.transfrinc.com, and https://supportcenter.transfrinc.com
  • *.transfrvr.com — including https://dashboard-api.transfrvr.com and https://insights-api.transfrvr.com
  • *.tx-xr.com — including https://ce-student-experience.tx-xr.com, https://ooh-service.tx-xr.com/, and https://core-auth.tx-xr.com/
  • https://transfrvr.fusionauth.io/oauth2/authorize
  • https://com-transfrvr-prod1.collector.snplow.net/i
  • https://www.gstatic.com and https://fonts.gstatic.com

ManageXR endpoints

ManageXR is the device-management platform that keeps your headsets on the configuration Transfr sets, so its traffic has to pass your firewall too. Allow the following:

  • us-central1-mighty-platform-prod.cloudfunctions.net — 443, TCP (HTTPS) — ManageXR API
  • mighty-platform-prod.appspot.com — 443, TCP (HTTPS) — ManageXR API
  • mighty-platform-prod.firebaseio.com — 443, TCP (HTTPS) — ManageXR API
  • managexrapi.com — 443, TCP (HTTPS) — ManageXR API
  • *.managexr.com — 443, TCP (HTTPS) — ManageXR API
  • *.googleapis.com — 443, TCP (HTTPS and WebSockets) — Google Cloud Platform APIs used by ManageXR
  • *.crashlytics.com — 80 and 443, TCP (HTTP and HTTPS) — error reporting. Optional: districts may keep port 80 closed without affecting day-to-day use.
  • openrelay.metered.ca — 80 and 443, UDP and TCP (HTTP and HTTPS) — realtime device streaming
  • managexrcdn.com — 443, TCP (HTTPS) — app and file downloads

Enterprise (802.1X) networks

Quest 2 and Quest 3S headsets connect to WPA, WPA2, and WPA3-Enterprise networks. On an enterprise network you can set the EAP method (PEAP, TLS, TTLS, or PWD), Phase 2 authentication (MSCHAPV2 or GTC), and how the headset handles the CA certificate (use system certificates, or do not validate).

For the Pico Neo 3, check with Transfr Technical Support.

Bandwidth

Day-to-day training needs very little bandwidth — roughly what sending and receiving Word documents needs. A typical training session moves about 50 MB in total for login authentication and data upload.

  • Recommended connection: 20 Mbps or better. That is the overall speed of the connection, not a figure per headset — a cart of headsets on a 20 Mbps line is fine.
  • Software updates: 1–8 GB per update, which needs more bandwidth. Transfr schedules updates around your availability, so the large downloads don't land in the middle of a class.

Still need help?

Contact our support team — Monday–Friday, 8am–8pm ET, 646-466-2600, technicalsupport@transfrvr.com.

Last updated: August 3, 2026

Search icon

Looking for something else?

Email icon

Still need help?

Contact support