Will a VPN give my Make.com scenarios a fixed IP address?

Summary

No. A Make scenario runs on Make's servers, not on your computer, so a VPN you connect to on your laptop never touches the request your scenario sends. If the service you are calling has an IP allowlist, the usual fix is to add the three egress IP addresses Make publishes for your zone. For a service that accepts only one address, Make's HTTP module can send the request through a proxy with a fixed exit IP, and for systems inside your own network there is the on-premise agent.

Where the request actually comes from

Picture a scenario that calls a warehouse's stock API every time a Shopify order arrives. The stock API sees a connection from Make, because that is where the scenario runs. Turn your laptop VPN on or off and the API's logs show the same source address.

Buying a dedicated IP from a VPN provider does not change that. Unless something routes Make's outbound request through that VPN, the request never leaves from the dedicated address.

Make publishes the addresses to allowlist

Make's help center lists its outbound (egress) IP addresses by zone. There are six zones on the page: us1, us2, eu1, eu2, us1.make.celonis.com and eu1.make.celonis.com, each with three addresses. If the service you are calling lets you allowlist several IPs, adding the three for your organization's zone is the whole job.

We don't copy the addresses here, so there is nothing on this page to go stale when Make updates its list.

The same page says Make uses dynamic IPs for inbound traffic. If you were hoping to restrict a webhook sender so it only talks to Make's IPs, there is no fixed list to use.

When the service accepts one address only

The Make a request module in Make's HTTP app (version 4) has a proxy option under Advanced settings. You create it as a keychain and fill in:

A proxy on its own does not give you a single fixed address. The service you are calling sees the proxy's exit IP, so you need a proxy provider that gives you a static exit address before you have one IP to allowlist.

The proxy field appears only in Make a request's settings. Make's documentation doesn't list it for the HTTP app's other modules, such as Download a file, and says nothing about app modules such as Shopify or Google Sheets using it. For an endpoint that insists on one IP, plan on rebuilding that call as a Make a request step.

Reaching systems inside your own network

Make's on-premise agent is for internal APIs and databases that aren't reachable from the internet. It is available to Enterprise customers, and for now the only agent type is the HTTP agent, which connects to internal systems that expose an API or web service. One agent can serve several applications on the same network.

The machine running the agent needs Java 11 or later, and Make has install instructions for Windows, macOS and Linux. Only users with the Owner, Admin or App Dev organization role can set it up. Make checks the agent every four minutes. When the agent's internet connection drops, its status becomes Not responding, and although the scenario keeps running, any module that uses the agent returns a 500 error.

How long Make keeps retrying a failed call

With incomplete executions turned on, Make automatically retries executions left incomplete by a RateLimitError, ConnectionError or ModuleTimeoutError. It tries eight more times, on this schedule:

AttemptWait since the previous tryTime since the original run
11 minute1 minute
210 minutes11 minutes
310 minutes21 minutes
430 minutes51 minutes
530 minutes1 hour 21 minutes
630 minutes1 hour 51 minutes
73 hours4 hours 51 minutes
83 hours7 hours 51 minutes

If all eight fail, Make marks the execution unresolved and leaves it for you. A scenario can have at most three of these retries running at once.

With incomplete executions turned off, Make reruns the scenario after a ConnectionError or ModuleTimeoutError at 1 minute, 2, 5 and 10 minutes, then 1, 3, 12 and 24 hours. If the eighth rerun fails, Make stops scheduling the scenario.

Other error types are not retried automatically by default. For calls that create orders or take payments, a retry means the same request can arrive twice, which is why APIs of that kind often accept an idempotency key.

When a VPN price comparison becomes relevant

Cost comes into it once you are shopping for a proxy or gateway with a fixed exit IP. Our page on dedicated IP and gateway cost lists what business VPN and zero-trust vendors charge for a dedicated IP address or dedicated gateway, and what that works out to per person at your team size.

Sources

Related on this site


Written by Kaz (pen name). Published September 28, 2026. The facts above come from the vendor and standards pages listed under Sources. We have not used these products. Corrections: contact form.