> ## Documentation Index
> Fetch the complete documentation index at: https://docs.boxd.sh/llms.txt
> Use this file to discover all available pages before exploring further.

# Egress allowlist

> Limit what a machine can reach on the internet, from the console, the CLI, or the SDKs.

By default a machine can reach anything on the internet. An egress allowlist narrows that to the hosts and addresses you name. Everything else is refused at the edge of the machine, before it leaves the host.

The allowlist is set from the outside: the machine's **Networking** tab in the console, `boxd machine egress` on the CLI, or the SDKs. There is deliberately no way to change it from inside the machine. A process with root in the machine cannot widen its own allowlist.

## Entries

An entry is one of:

| Entry | Matches |
| - | - |
| `api.stripe.com` | that hostname |
| `*.example.com` | every subdomain |
| `203.0.113.7` | one public IPv4 address |
| `203.0.113.0/24` | a CIDR range |

HTTP and HTTPS are admitted by hostname. Everything else, an SSH connection or a database port for example, is admitted by address. Provider-wide wildcards such as `*.amazonaws.com` are refused.

The hosts of any [host-bound secret](/guides/env-secrets#host-bound-secrets) the machine holds are always admitted, on top of the list, so a secret bound to `api.stripe.com` keeps working under an allowlist that does not name it.

## Set it

```bash theme={"theme":"github-dark"}
boxd machine egress myapp                                  # show the current allowlist
boxd machine egress myapp api.stripe.com,*.github.com      # replace it (comma-separated)
boxd machine egress myapp --clear                          # back to unrestricted
```

The list you pass is the complete new allowlist, not an addition. An empty allowlist means unrestricted.

In the console, open the machine, then **Networking**, then **Edit** next to the egress allowlist. The change takes effect immediately, without a reboot, and shows up on every surface at once.

## From the SDKs

```python theme={"theme":"github-dark"}
boxd.machines.set_egress_allow(machine.id, ["api.stripe.com", "*.github.com", "203.0.113.0/24"])
boxd.machines.get(machine.id).egress_allow
boxd.machines.set_egress_allow(machine.id, [])   # unrestricted again
```

```typescript theme={"theme":"github-dark"}
await boxd.machines.setEgressAllow(machine.id, ["api.stripe.com", "*.github.com"]);
(await boxd.machines.get(machine.id)).egressAllow;
await boxd.machines.setEgressAllow(machine.id, []);
```

## What it is for

An allowlist turns a machine into a place where an agent or a job can run with a known set of destinations: the model provider, your own API, the package registry. Combine it with an [isolated](/use-cases/sandboxes) machine and with host-bound secrets, and the machine can neither reach what it should not nor leak a credential to where it should not go.
