penduses Check my setup

Managed static egress · Dedicated IPv4

Your own static IP. For outbound API calls.

Get your IP. Connect your app. Keep building. Connect with the Penduses SDK.
We manage your egress and keep your IP fixed across deployments.

Give your partner an IP to allowlist.

For the API, webhook or business system that will only accept requests from an approved IP. Start with a compatible server-side HTTP(S) client.

  1. 1

    Get your dedicated IP

    Give this address to the partner whose API you need to reach.

    Your app
    Your existing application
    Outbound IP
    203.0.113.25
    Valid
    While your service stays allocated

    Redeploying your app does not change the IP allocated to your Penduses service.

  2. 2

    Choose allowed destinations

    Your partner allows connections from your IP.

    Your partner allows
    203.0.113.25
    You allow
    198.51.100.42:443
    Anything else
    Refused

    You choose which destinations your service can reach by adding them to your Penduses allowlist. Requests to unlisted destinations are refused.

  3. 3

    Verify the connection

    Check your outbound IP, then make a real request to your partner’s API.

    await egress.verifyIp(echoUrl)
    expectedIp
    203.0.113.25
    observedIp
    203.0.113.25
    ok
    true

    The IP check is the first step. Confirm that the real API call succeeds and that your partner sees the assigned address.

The board, addresses and responses are illustrative examples, not live test results.

Keep your code. Route the calls that matter.

This Node.js example shows the connection path. Send an API call through egress.fetch; ordinary fetch calls keep their existing route.

egress-example.mjsNode.js, server-side
import { createEgress } from '@penduses/egress';

const egress = createEgress({
  endpoints: [{
    host: process.env.PENDUSES_HOST,
    httpPort: Number(process.env.PENDUSES_HTTP_PORT),
    username: process.env.PENDUSES_USER,
    password: process.env.PENDUSES_PASSWORD,
    tls: true,
  }],
  expectedIp: process.env.PENDUSES_EXPECTED_IP,
});// Use an HTTPS IP-echo endpoint you trust.
// Add its destination to your allowlist first.
const { observedIp, ok } = await egress.verifyIp(
  process.env.PENDUSES_ECHO_URL
);
console.log({ observedIp, ok });// TARGET_URL must also be on your allowlist.
const response = await egress.fetch(
  process.env.TARGET_URL
);
console.log(response.status);
  1. 1

    Configure

    Set the endpoint hostname, port, credentials and expected IP supplied for your service. Keep credentials on the server. The endpoint hostname must match its TLS certificate.

  2. 2

    Verify

    Add an HTTPS IP-echo endpoint you trust to your destination allowlist, then call egress.verifyIp to check the outbound address.

  3. 3

    Connect

    Add your API destination to the allowlist and call it with egress.fetch. Your partner’s API authentication still applies.

Before you run the example

  • Use Node.js 20.18.1 or newer.
  • Install the SDK from the repository. It is not yet published to npm.
  • Run it on the server. The SDK does not support Edge Runtime or browsers.

Will it fit your stack?

Vercel / Next.js is our starting point. On another platform? Tell us your runtime and target so we can check the actual connection before you choose a plan.

Your setupHow it connectsFit
Vercel and Next.jsNode.js runtime Use the SDK in server-side Node.js Route Handlers for outbound HTTP(S) requests. HTTP(S) path
Partner HTTP(S) APIsYour IP on their allowlist Connect over TLS using HTTP CONNECT. Your partner allowlists your dedicated IP. HTTP(S) path
Railway, Lambda or Cloud RunYour runtime and target matter A shared IP your partner refuses, or a few API calls that need their own address? We will review the client, network access and region with you. Check my setup
CI and scheduled jobsClients with HTTP CONNECT support Use the Node SDK or a client that supports HTTP CONNECT. The GitHub Action is available in the repository, without a standalone release yet. Review first
Edge Runtime or browser Move the request to a Node.js Route Handler. SDK not supported
Databases, SFTP and other TCP services These need a separate compatibility review. The HTTP(S) SDK example does not establish database or SFTP support; WireGuard requires a host you control. Ask about your setup

Your IP. Your destinations. Your existing app.

An IP your partner can approve

Your outbound address is allocated to your service and is not shared with other customer services. App redeploys do not change that allocation. Pro has two addresses; your partner must allow both.

Managed egress. Encrypted connections.

We operate the egress infrastructure. The SDK verifies the service’s TLS certificate before sending credentials. Keep those credentials on your server; your partner’s own API authentication still applies.

Only the destinations you choose

Choose which destination IPs and ports the service can reach. Calls through Penduses to other destinations are refused. Requests you do not route through Penduses keep their existing path.

No direct fallback

If the SDK cannot connect through its configured egress endpoints, it returns an error. Pro can try a second endpoint for eligible connection failures before a request is sent. Requests that may already have been sent are not replayed.

Start with the connection you need.

Tell us about your integration. We will confirm compatibility, region, monthly price, included usage and limit behavior in your pilot quote before you commit.

Starter

One IP

For an API integration that needs one dedicated source IP.

Addresses
1 dedicated outbound IPv4
Region
One available region
Connection
TLS-fronted HTTP CONNECT
Connection path
One endpoint
Destinations
Your allowlist
Price and included traffic
Confirmed in your quote

Pro

Two IPs

For integrations that need a second connection path and can allow two IPs.

Addresses
2 dedicated outbound IPv4
Region
Two regions
Connection
TLS-fronted HTTP CONNECT
Second endpoint
SDK failover for eligible new connections
Destinations
Your allowlist; allow both IPs at your destination
Price and included traffic
Confirmed in your quote

Keep the plan price you start with.

The recurring price of the plan you purchase stays fixed until you cancel. Upgrade later and the current price of the higher plan applies.

Price protection covers your purchased plan, not every future plan or usage charge. Your quote will specify included usage, any additional charges and cancellation terms. Pilot service: best effort, no SLA.

Before you connect

Still unsure? Email us your setup.

Do I need to move my app or route all its traffic?

No. Keep your existing deployment and route the selected server-side HTTP(S) requests through Penduses. Our Next.js example uses the Node.js runtime. Other platforms and clients need a compatibility check; this is not a switch for all project traffic.

Does every request use my Penduses IP?

Only requests explicitly routed through Penduses. Other traffic keeps its existing route. If your application uses separate service identities for different tenants, use a separate client for each identity.

When can my IP change?

Redeploying your app does not change its Penduses allocation. Ending the service releases the address. Discuss migrations or service changes with us so you can account for any required allowlist updates.

Can I connect to PostgreSQL, MongoDB or SFTP?

The fetch example covers HTTP(S), not database or SFTP clients. Send us your runtime, client and destination for a separate review. WireGuard on a server you control is a different setup; it does not mean WireGuard runs inside a Vercel Function.

What happens if a connection fails?

With one endpoint, the SDK returns an error. With Pro, eligible connection failures can trigger an attempt through the second endpoint before the request is sent.

Existing connections are not moved. Requests that may have been sent are not replayed. Authentication, certificate and destination-policy errors must be resolved. The SDK does not fall back to a direct connection.

How do I check which IP my partner sees?

Start with an allowed HTTPS IP-echo endpoint and compare the observed address with your expected IP. Then make a real request using your actual API client and confirm the result with your partner. A successful IP check alone does not prove every library uses the same route.

Which region should I use?

Choose from the available regions with your application and destination in mind. Routing through Penduses adds a network hop, so measure actual request times during the pilot.

What will it cost? What happens at the traffic limit?

Your pilot quote will state the monthly price, included transfer, connection limits and what happens when you reach them. Send a rough usage estimate, or tell us if you do not know it yet. Your hosting provider may still charge for outbound traffic.

My platform already offers static IPs. Why use Penduses?

Its built-in option may be enough. Penduses is worth checking when your partner requires an IP dedicated to your service, you want to route only selected API calls, or you do not want to operate your own egress infrastructure. Compare the full setup and usage costs; a lower total bill depends on your workload.

Can several apps use the same service?

Tell us which apps, environments and customers you need to connect. Shared usage counts toward the service’s limits. Different customer identities may need separate IPs and credentials; we will confirm the arrangement before quoting.

What happens when the target API changes its IP?

The destination allowlist uses IP addresses and ports. A hostname or CDN can resolve to different addresses, so its required destinations need to stay on the list. We will review this during setup; it is separate from keeping your own source IP fixed.

Does this give my Vercel app a fixed inbound IP?

No. Static Egress handles outbound connections. For routed inbound and outbound IPv4 on a host you control, ask about Tunnel IP.

Need inbound connectivity or an IPv4 block?

Tunnel IP

Routed public IPv4 over WireGuard for a host you control. Discuss /32, /29 or /28 options for inbound and outbound connectivity.

Ask about Tunnel IP

Managed /24

IPv4 blocks for hosting companies and network operators. Contact us about routing, address management and commercial terms.

Discuss a block

Let’s get your partner connection unstuck.

Tell us where your app runs, which API you need to reach and whether the partner requires a dedicated IP. A rough usage estimate helps; “not sure yet” is fine.

We will check the setup and send a pilot proposal with scope, price and next steps. We operate the address space and servers behind Penduses.

Email my setup hello@penduses.com