Whitelisting SuperPath for Email and App Access
Whitelisting SuperPath for Email and App Access
In this article:
- Overview
- Why whitelisting matters
- What to whitelist
- Steps for your IT team
- Things to keep in mind
Overview
Some corporate networks restrict email and website traffic with firewalls or filtering rules. To make sure SuperPath works smoothly, your IT team may need to allowlist (whitelist) a few domains and email addresses. This is a reference for the addresses and domains to allow.
Without them, your people may experience:
- Emails that are delayed, undelivered, or land in spam
- Sign-in problems when using magic links or other email notifications
- Courses not syncing correctly across tabs or between users
Whitelisting SuperPath improves email deliverability, keeps authentication secure, and keeps the platform running seamlessly.
Why whitelisting matters
Many organisations run strict network and email security policies. This improves safety, but it can sometimes block important services. SuperPath relies on real-time updates (over web sockets) to keep courses and collaboration in sync, so if your firewall blocks these you may see broken functionality.
Whitelisting ensures that:
- Emails are delivered reliably, so sign-in links and notifications always arrive
- Authentication is secure and uninterrupted
- Real-time course sync is maintained for a smooth learning experience
What to whitelist
- noreply@superpath.io — all SuperPath emails (sign-in links, notifications, reminders) come from this address. Adding it to your safe-senders list ensures nothing is blocked.
Websites
- app.superpath.io (or your custom SuperPath domain) — the main platform URL your learners access on the US data region.
- app-au.superpath.io (or your custom SuperPath domain) — the main platform URL your learners access on the AU data region.
- superpath-prod.firebaseapp.com — used for authentication. We're working to change this, but for now it must remain whitelisted.
- track.pstmrk.it — our email tracking service (Postmark), which helps us monitor deliverability and security.
- app.mindsmith.ai — powers SuperPath's AI Course Builder (provided by our partner MindSmith); needed for authoring and playing AI-built courses.
- Web socket traffic — make sure your network allows web socket connections. This keeps courses and collaboration updated in real time.
Steps for your IT team
- Add noreply@superpath.io to your organisation's safe senders or allowlist.
- Add the domains listed above to your firewall or proxy whitelist.
- Confirm that web socket connections are permitted across your network.
- Test by signing in to SuperPath and opening a course in two tabs — updates should sync instantly.
Things to keep in mind
- You only need the data-region URL that applies to your account (US or AU), plus any custom SuperPath domain you use.
- If you use SAML SSO, your identity provider's own domains may also need allowlisting, depending on your setup.
- Once these domains and addresses are whitelisted, your team will have uninterrupted access to SuperPath, with reliable email delivery and real-time collaboration.
Updated on: 24/07/2026
Thank you!
