A static IP for AWS security groups and database allowlists

GetAStatic is a WireGuard VPN with your own fixed IPv4, from $2/mo. Run it on your laptop or router and add that one /32 to your security group, RDS, Atlas or API allowlist. It keeps working when your home IP changes.

Instant setup US-based IP

Updated

The problem

Your IP changes, your security group does not

AWS security groups, RDS, MongoDB Atlas, managed Postgres, API gateways, GitHub IP allow lists and SaaS admin portals let in only the addresses you list. Home internet can get a new IP after a router restart. A laptop gets a new one on every network. Each change locks you out of SSH, the database or the admin page.

The usual workarounds cost time or safety. Scripts and Lambda functions that rewrite the rule can break without warning. Opening port 22 or 5432 to 0.0.0.0/0 exposes the server to the whole internet. Behind CGNAT, common on 5G home internet and Starlink, your public IP is shared with other customers, so allowing it lets them in too.

Your own static IP over WireGuard. No VPS.

Dedicated IPv4 from $2/mo →
Why use GetAStatic?

Why developers use GetAStatic for allowlists

  • One /32 rule instead of a script that rewrites your security group
  • The same IP from home, a café, a phone hotspot or behind CGNAT
  • Your own dedicated IPv4, never shared with other customers
  • From $2/mo; Pro includes 2 IPs for a small team
How it works

One fixed egress IP for each machine that needs access

GetAStatic gives you a dedicated public IPv4 in Kansas City, Missouri or San Jose, California. Install WireGuard and import the config we generate. The device dials out to our node, and AWS, Atlas or GitHub sees your static IP. You open no inbound ports for this: an allowlist only checks outgoing traffic.

Put the tunnel on the laptop you work from, or on your router so every machine at home or in a small office leaves from the same IP. Remote employees who work from different places each get their own IP, and you add each /32 to the list.

By default the config sends all of the device's traffic through the tunnel, so every tool on it uses the static IP: the AWS CLI, Terraform, a database client, SSH and the browser.

Setup

Add your static IP to AWS, RDS or Atlas

  1. Choose a plan and sign up. Your new IP shows in the dashboard.
  2. Install WireGuard on the laptop or router that needs access. Import the config and turn the tunnel on.
  3. Open any what-is-my-IP site. It should show your new IP.
  4. AWS: in the EC2 console, edit the inbound rules of the security group. Add a rule for SSH (22), Postgres (5432), MySQL (3306) or the port you use, with the source YOUR-IP/32. For RDS, edit the security group attached to the database.
  5. MongoDB Atlas: open Network Access, then IP Access List, and add YOUR-IP. GitHub Enterprise Cloud: organization settings, Authentication security, IP allow list. Most SaaS admin portals have a similar trusted-IP setting.
  6. Remove the old home-IP rules and any 0.0.0.0/0 rule you added as a workaround.

Leave the ports page in the dashboard alone. An allowlist needs no open ports on our side.

Good to know

Good to know

  • It is a datacenter IP in Kansas City, Missouri or San Jose, California. AWS, databases and APIs treat it like any other address; a few consumer fraud systems treat datacenter IPs more strictly.
  • Traffic goes through Kansas City, Missouri or San Jose, California before it reaches AWS. New orders get the default city. If you are far from the IP's city, or your servers are in a distant region, expect added latency.
  • Speed is capped by plan: 20 Mbps on Plus, 100 Mbps on Pro, 1 Gbps on Ultra. Large database dumps take longer than on a direct link.
  • Each IP is one WireGuard config, active on one device at a time. Run it on a router and every device behind it shares the IP; the plan card's device figure is a guide, not a cap. Or give each person an IP: Pro includes 2, and an extra IP is $2/mo.
  • There is no admin console, SSO or per-user policy. One account manages its IPs.
Pricing

Choose your plan

Plus for light use, Pro for most people, Ultra for full gigabit.

Plus
$2/mo

 

  • 1 dedicated IP address
  • 10 devices
  • 5 open ports
  • 100 GBbandwidth
  • 20 Mbpsspeed
Ultra
$10/mo

 

  • 2 dedicated IP addresses
  • Unlimited devices
  • Unlimited open ports
  • 5 TBbandwidth
  • 1 Gbpsspeed
  • Inbound + outbound access
  • Instant activation
  • 7-day money-back guarantee
  • Cancel anytime
Add-ons, per IP addressCustom hostname $5·Addtl. IP $2/mo (Ultra $7/mo)·Gigabit Speed (Plus & Pro) $5/mo·SMTP $25
FAQ

Questions, answered.

01Can a whole office share one IP?

Yes. Run WireGuard on the office router (OpenWrt, pfSense, OPNsense, MikroTik or GL.iNet), and every device behind it leaves from the same IP. Add that one /32 to the allowlist. People who work from home need their own IP or a router tunnel at home.

02Does it work with Okta or Microsoft Entra ID IP policies?

Yes. Okta network zones and Entra ID named locations accept a single IP address. Add YOUR-IP/32 and mark it as trusted. While the tunnel is on, the identity provider sees your static IP at every sign-in.

03Can I send only AWS traffic through the tunnel?

No. The config sends all of the device's traffic through the tunnel (AllowedIPs = 0.0.0.0/0). We support the config as we ship it; editing AllowedIPs is unsupported. The full tunnel also means every tool on the device, from the AWS CLI to SSH, uses your static IP.

04Is the IP ever reused?

Not while it is yours. The IP is assigned to you alone for as long as your plan is active, and if a payment fails we hold it for at least 30 days. After you cancel, it is released at the end of the paid period and can go to a new customer, so remove it from every allowlist when you leave.

05Do I need to open any ports?

No. An allowlist checks only the address your traffic comes from. A new IP starts with every inbound port closed, and you can leave it that way. To reach a machine at home from outside later, open ports in the dashboard: 5 open ports on Plus, unlimited open ports on Pro.

Have more questions? See the full FAQ →