Firewall IP
Multi-cloud · AWS security groups & GCP Cloud SQL

Temporary IP allowlisting, self-service from Slack.

Firewall IP lets your Slack members request time-boxed access to AWS security groups and GCP Cloud SQL with a single Slack command. Approved, auto-expiring, fully audited — and nobody touches the cloud console.

Free for 1 project — no credit card required.

Firewall IP Direct message

you /firewall-ip add

Add IP request

Project
prod-api
IP address
leave blank → autodetect
Expires after
7 days

Approved — 203.0.113.24/32 added to prod-api.

Expires in 7 days · we’ll remind you before it does.

Beyond bastions & VPNs

Skip the bastion host and VPN gymnastics

Bastions and VPNs are the traditional way into secure internal systems — and they’re costly to maintain and easy for everyday users to get wrong. Firewall IP leans on the authentication you already trust in Slack, so people grant themselves exactly the access they need.

The old way — bastions & VPNs

  • Bastion hosts to patch, monitor, and pay for around the clock.
  • VPN clients to install, configure, and debug on every device.
  • Fiddly for the average user — and a ticket to ops every time.

With Firewall IP

  • Nothing to install — access lives in Slack, where your team already is.
  • Rides on your Slack authentication, including your workspace’s 2FA.
  • Members self-serve in seconds; grants are scoped and auto-expire.

Features

Everything you need to grant access safely

Firewall IP replaces console clicks and long-lived firewall rules with short-lived, self-service grants — approved and audited end to end.

One bot, multiple clouds

Manage AWS security group ingress rules and GCP Cloud SQL authorized networks side by side — from the same Slack command, with per-project cloud accounts.

Self-service in Slack

Developers run /firewall-ip add, list, or remove right in a DM. Pick a project, request an IP, done — no cloud console, no tickets, no waiting on ops.

Auto-expiring access

Every grant carries a TTL — 1, 3, 7, 14, 30 days, or a project default. An hourly sweeper revokes expired rules automatically and warns owners ~24h before.

Autodetect your IP

Leave the IP blank and the bot DMs a single-use magic link. Click Confirm and it captures your real public IP — no “what’s my IP” hunting behind VPNs or NAT.

Approvals your way

Enable auto-approve per project for low-risk access, or route requests to designated approvers who get a private DM with Approve / Reject. The TTL clock starts at approval.

Drift detection

A daily reconcile compares each project against the live cloud. Rules changed outside the bot are flagged, the original requester is DM’d, and untracked rules are surfaced to approvers.

Full audit trail

Every request, approval, add, removal, expiry, and eviction is appended to an immutable log, with a Recent Activity feed in the Slack Home tab.

Least-privilege roles

Slack admins, Bot Admins, project approvers, and members — including channel-based membership — each get exactly the access they need, backed by scoped cloud credentials.

How it works

From install to auto-expiry in four steps

  1. 1

    Add to Slack

    Install Firewall IP into your workspace in a couple of clicks. Bot tokens are stored securely so the bot survives scale-to-zero.

  2. 2

    Configure a project

    A Bot Admin connects an AWS security group or a GCP Cloud SQL instance with least-privilege credentials, sets the default TTL, and picks auto-approve or approvers. A one-click Test validates permissions before it goes live.

  3. 3

    Members request IPs

    Run /firewall-ip add in a DM, pick the project, and enter an IP — or leave it blank to autodetect. Auto-approve applies it instantly; otherwise an approver gets a DM.

  4. 4

    Access auto-expires

    Rules clean themselves up when their TTL is reached. Owners get a heads-up DM before expiry and simply re-request to refresh. Nothing lingers.

Pricing

Simple, flat pricing per workspace

Every plan includes every feature and unlimited members — you only pay for more projects. Flat, per workspace, no usage metering. Save up to 30% billed annually.

Free

$0 /mo

$0 /mo

Kick the tires on a single project.

1 project

Everything included

  • AWS security groups & GCP Cloud SQL
  • Autodetect & auto-expiring (TTL) access
  • Approvals with designated approvers
  • Drift detection & daily reconcile
  • Full audit trail & Recent Activity feed
  • Roles & channel-based membership
Add to Slack

Starter

$10 /mo

$8 /mo Save 20%

billed $96/yr

For access across a couple of environments.

2 projects

Everything included

  • AWS security groups & GCP Cloud SQL
  • Autodetect & auto-expiring (TTL) access
  • Approvals with designated approvers
  • Drift detection & daily reconcile
  • Full audit trail & Recent Activity feed
  • Roles & channel-based membership
Subscribe
Most popular

Pro

$20 /mo

$15 /mo Save 25%

billed $180/yr

Room to grow, for most teams.

5 projects

Everything included

  • AWS security groups & GCP Cloud SQL
  • Autodetect & auto-expiring (TTL) access
  • Approvals with designated approvers
  • Drift detection & daily reconcile
  • Full audit trail & Recent Activity feed
  • Roles & channel-based membership
Subscribe

Business

$50 /mo

$35 /mo Save 30%

billed $420/yr

Standardize access org-wide.

20 projects

Everything included

  • AWS security groups & GCP Cloud SQL
  • Autodetect & auto-expiring (TTL) access
  • Approvals with designated approvers
  • Drift detection & daily reconcile
  • Full audit trail & Recent Activity feed
  • Roles & channel-based membership
Subscribe

FAQ

Questions, answered

Still curious? Reach out on the support page.

Which clouds does Firewall IP support?

Two today: AWS security group ingress rules and GCP Cloud SQL authorized networks. Each project connects to one of them, and a single bot can manage a mix of both across your workspace.

Do developers need cloud console access?

No. That’s the point. Everything happens through the /firewall-ip slash command in Slack — add, list, and remove IPs from a DM. Developers never touch the AWS or GCP console.

How does access expire?

Every grant has a TTL (1, 3, 7, 14, or 30 days, or your project default). An hourly job revokes rules once they expire and DMs the owner about 24 hours beforehand so they can re-request if they still need it.

What is autodetect?

Leave the IP field blank when you request access and the bot DMs you a single-use magic link. Clicking Confirm captures your browser’s real public IP and adds it — no guessing your address behind a VPN or NAT.

How do approvals work?

It’s per project. Turn on auto-approve for low-risk access, or route requests to designated approvers who receive a private DM with Approve and Reject buttons. When manual approval is on, the TTL clock only starts once the request is approved.

What happens if someone changes a rule directly in the cloud?

A daily reconcile compares each project against the live provider. If a bot-managed rule was removed out-of-band, the original requester and the project’s approvers are notified. Rules added outside the bot are surfaced as untracked — the bot never silently deletes them.

Is there an audit trail?

Yes — an append-only log records every request, approval, rejection, add, removal, expiry, and eviction. The Slack Home tab also shows a Recent Activity feed of the latest changes.

How is billing handled?

Four flat tiers per workspace — Free, Starter, Pro, and Business — with no usage metering. Pick monthly or annual billing (annual saves up to 30%). Start free on one project and upgrade in Slack when you need more.

Stop handing out standing access

Give your team self-service, time-boxed cloud access from Slack. Set up your first project in minutes — free.