Temporary IP allowlisting, self-service from Slack.
Firewall IP lets your Slack members request time-boxed access to AWS security groups and GCP Cloud SQL with a single Slack command. Approved, auto-expiring, fully audited — and nobody touches the cloud console.
Free for 1 project — no credit card required.
you /firewall-ip add
Add IP request
- Project
- prod-api
- IP address
- leave blank → autodetect
- Expires after
- 7 days
Approved — 203.0.113.24/32 added to prod-api.
Expires in 7 days · we’ll remind you before it does.
Skip the bastion host and VPN gymnastics
Bastions and VPNs are the traditional way into secure internal systems — and they’re costly to maintain and easy for everyday users to get wrong. Firewall IP leans on the authentication you already trust in Slack, so people grant themselves exactly the access they need.
The old way — bastions & VPNs
- Bastion hosts to patch, monitor, and pay for around the clock.
- VPN clients to install, configure, and debug on every device.
- Fiddly for the average user — and a ticket to ops every time.
With Firewall IP
- Nothing to install — access lives in Slack, where your team already is.
- Rides on your Slack authentication, including your workspace’s 2FA.
- Members self-serve in seconds; grants are scoped and auto-expire.
Features
Everything you need to grant access safely
Firewall IP replaces console clicks and long-lived firewall rules with short-lived, self-service grants — approved and audited end to end.
One bot, multiple clouds
Manage AWS security group ingress rules and GCP Cloud SQL authorized networks side by side — from the same Slack command, with per-project cloud accounts.
Self-service in Slack
Developers run /firewall-ip add, list, or remove right in a DM. Pick a project, request an IP, done — no cloud console, no tickets, no waiting on ops.
Auto-expiring access
Every grant carries a TTL — 1, 3, 7, 14, 30 days, or a project default. An hourly sweeper revokes expired rules automatically and warns owners ~24h before.
Autodetect your IP
Leave the IP blank and the bot DMs a single-use magic link. Click Confirm and it captures your real public IP — no “what’s my IP” hunting behind VPNs or NAT.
Approvals your way
Enable auto-approve per project for low-risk access, or route requests to designated approvers who get a private DM with Approve / Reject. The TTL clock starts at approval.
Drift detection
A daily reconcile compares each project against the live cloud. Rules changed outside the bot are flagged, the original requester is DM’d, and untracked rules are surfaced to approvers.
Full audit trail
Every request, approval, add, removal, expiry, and eviction is appended to an immutable log, with a Recent Activity feed in the Slack Home tab.
Least-privilege roles
Slack admins, Bot Admins, project approvers, and members — including channel-based membership — each get exactly the access they need, backed by scoped cloud credentials.
How it works
From install to auto-expiry in four steps
- 1
Add to Slack
Install Firewall IP into your workspace in a couple of clicks. Bot tokens are stored securely so the bot survives scale-to-zero.
- 2
Configure a project
A Bot Admin connects an AWS security group or a GCP Cloud SQL instance with least-privilege credentials, sets the default TTL, and picks auto-approve or approvers. A one-click Test validates permissions before it goes live.
- 3
Members request IPs
Run /firewall-ip add in a DM, pick the project, and enter an IP — or leave it blank to autodetect. Auto-approve applies it instantly; otherwise an approver gets a DM.
- 4
Access auto-expires
Rules clean themselves up when their TTL is reached. Owners get a heads-up DM before expiry and simply re-request to refresh. Nothing lingers.
Pricing
Simple, flat pricing per workspace
Every plan includes every feature and unlimited members — you only pay for more projects. Flat, per workspace, no usage metering. Save up to 30% billed annually.
Free
Kick the tires on a single project.
Everything included
- AWS security groups & GCP Cloud SQL
- Autodetect & auto-expiring (TTL) access
- Approvals with designated approvers
- Drift detection & daily reconcile
- Full audit trail & Recent Activity feed
- Roles & channel-based membership
Starter
billed $96/yr
For access across a couple of environments.
Everything included
- AWS security groups & GCP Cloud SQL
- Autodetect & auto-expiring (TTL) access
- Approvals with designated approvers
- Drift detection & daily reconcile
- Full audit trail & Recent Activity feed
- Roles & channel-based membership
Pro
billed $180/yr
Room to grow, for most teams.
Everything included
- AWS security groups & GCP Cloud SQL
- Autodetect & auto-expiring (TTL) access
- Approvals with designated approvers
- Drift detection & daily reconcile
- Full audit trail & Recent Activity feed
- Roles & channel-based membership
Business
billed $420/yr
Standardize access org-wide.
Everything included
- AWS security groups & GCP Cloud SQL
- Autodetect & auto-expiring (TTL) access
- Approvals with designated approvers
- Drift detection & daily reconcile
- Full audit trail & Recent Activity feed
- Roles & channel-based membership
Which clouds does Firewall IP support?
Two today: AWS security group ingress rules and GCP Cloud SQL authorized networks. Each project connects to one of them, and a single bot can manage a mix of both across your workspace.
Do developers need cloud console access?
No. That’s the point. Everything happens through the /firewall-ip slash command in Slack — add, list, and remove IPs from a DM. Developers never touch the AWS or GCP console.
How does access expire?
Every grant has a TTL (1, 3, 7, 14, or 30 days, or your project default). An hourly job revokes rules once they expire and DMs the owner about 24 hours beforehand so they can re-request if they still need it.
What is autodetect?
Leave the IP field blank when you request access and the bot DMs you a single-use magic link. Clicking Confirm captures your browser’s real public IP and adds it — no guessing your address behind a VPN or NAT.
How do approvals work?
It’s per project. Turn on auto-approve for low-risk access, or route requests to designated approvers who receive a private DM with Approve and Reject buttons. When manual approval is on, the TTL clock only starts once the request is approved.
What happens if someone changes a rule directly in the cloud?
A daily reconcile compares each project against the live provider. If a bot-managed rule was removed out-of-band, the original requester and the project’s approvers are notified. Rules added outside the bot are surfaced as untracked — the bot never silently deletes them.
Is there an audit trail?
Yes — an append-only log records every request, approval, rejection, add, removal, expiry, and eviction. The Slack Home tab also shows a Recent Activity feed of the latest changes.
How is billing handled?
Four flat tiers per workspace — Free, Starter, Pro, and Business — with no usage metering. Pick monthly or annual billing (annual saves up to 30%). Start free on one project and upgrade in Slack when you need more.
Stop handing out standing access
Give your team self-service, time-boxed cloud access from Slack. Set up your first project in minutes — free.