- 1 dedicated IP address
- 10 devices
- 5 open ports
- 100 GBbandwidth
- 20 Mbpsspeed
GetAStatic is a WireGuard VPN with your own fixed IPv4, from $2/mo. Run it on your laptop or router and add that one /32 to your security group, RDS, Atlas or API allowlist. It keeps working when your home IP changes.
Updated
AWS security groups, RDS, MongoDB Atlas, managed Postgres, API gateways, GitHub IP allow lists and SaaS admin portals let in only the addresses you list. Home internet can get a new IP after a router restart. A laptop gets a new one on every network. Each change locks you out of SSH, the database or the admin page.
The usual workarounds cost time or safety. Scripts and Lambda functions that rewrite the rule can break without warning. Opening port 22 or 5432 to 0.0.0.0/0 exposes the server to the whole internet. Behind CGNAT, common on 5G home internet and Starlink, your public IP is shared with other customers, so allowing it lets them in too.
Your own static IP over WireGuard. No VPS.
Dedicated IPv4 from $2/mo →GetAStatic gives you a dedicated public IPv4 in Kansas City, Missouri or San Jose, California. Install WireGuard and import the config we generate. The device dials out to our node, and AWS, Atlas or GitHub sees your static IP. You open no inbound ports for this: an allowlist only checks outgoing traffic.
Put the tunnel on the laptop you work from, or on your router so every machine at home or in a small office leaves from the same IP. Remote employees who work from different places each get their own IP, and you add each /32 to the list.
By default the config sends all of the device's traffic through the tunnel, so every tool on it uses the static IP: the AWS CLI, Terraform, a database client, SSH and the browser.
Leave the ports page in the dashboard alone. An allowlist needs no open ports on our side.
Plus for light use, Pro for most people, Ultra for full gigabit.
5× speed · 10× bandwidth · 2 IPs — only $2/mo more
Yes. Run WireGuard on the office router (OpenWrt, pfSense, OPNsense, MikroTik or GL.iNet), and every device behind it leaves from the same IP. Add that one /32 to the allowlist. People who work from home need their own IP or a router tunnel at home.
Yes. Okta network zones and Entra ID named locations accept a single IP address. Add YOUR-IP/32 and mark it as trusted. While the tunnel is on, the identity provider sees your static IP at every sign-in.
No. The config sends all of the device's traffic through the tunnel (AllowedIPs = 0.0.0.0/0). We support the config as we ship it; editing AllowedIPs is unsupported. The full tunnel also means every tool on the device, from the AWS CLI to SSH, uses your static IP.
Not while it is yours. The IP is assigned to you alone for as long as your plan is active, and if a payment fails we hold it for at least 30 days. After you cancel, it is released at the end of the paid period and can go to a new customer, so remove it from every allowlist when you leave.
No. An allowlist checks only the address your traffic comes from. A new IP starts with every inbound port closed, and you can leave it that way. To reach a machine at home from outside later, open ports in the dashboard: 5 open ports on Plus, unlimited open ports on Pro.
Have more questions? See the full FAQ →