To ensure Masterplan runs smoothly, your systems should meet the following requirements.
Supported Web Browsers
For the best experience, we recommend using the latest version of one of the following browsers:
- Google Chrome
- Mozilla Firefox
- Microsoft Edge
- Safari
Note: Always use the latest browser version to benefit from the newest features, performance improvements, and security updates.
Supported Mobile Devices
The Masterplan app is available for the following operating systems:
| Operating System | Supported Version |
|---|---|
| iPhone (iOS) | iOS 16.4 or later |
| iPad (iPadOS) | iPadOS 16.4 or later (partial support) |
| Android | Android 7.1 (API 25) or later |
Network Requirements
Masterplan is a cloud-based (SaaS) application that can be accessed either through a web browser or via the iOS and Android apps.
The web application requires only outbound HTTPS traffic over TCP port 443.
No additional ports, UDP/QUIC traffic, or local software installation are required.
Required Allowlist (Whitelist)
To ensure Masterplan functions correctly, your IT department should allow access to the following domains.
Masterplan Services
*.masterplan.comIf wildcard domains are not supported, allow the following individual hosts:
masterplan.com
app.masterplan.com
auth.masterplan.com
api.masterplan.com
media.masterplan.com
downloads.masterplan.com
scorm.masterplan.com
ph.masterplan.comVideo Delivery
The following domains are required for video playback:
customer-qqv9dy4gjtd32v0z.cloudflarestream.com
cdn.jsdelivr.netIf these domains are blocked, videos may remain stuck on the loading screen and never start playing.
File Storage (Amazon S3)
The following endpoints are used for file uploads and downloads:
masterplan-media-prod.s3.eu-central-1.amazonaws.com
masterplan-learnpath-uploads-prod.s3.eu-central-1.amazonaws.com
masterplan-scorm-uploads-prod.s3.eu-central-1.amazonaws.com
masterplan-user-data-prod.s3.eu-central-1.amazonaws.com
s3.eu-central-1.amazonaws.com
g7vg56hzje.execute-api.eu-central-1.amazonaws.comMobile Apps
For push notifications, the mobile apps also require access to:
fcmregistrations.googleapis.com
firebaseinstallations.googleapis.com
clients3.google.comIf push notifications are required on managed devices or corporate networks, please also follow Apple's and Google's published network requirements for their respective push notification services.
YouTube Content
If any course content includes YouTube-hosted videos, the following domains must also be reachable:
www.youtube.com
i.ytimg.comRemote SCORM
If Masterplan content is embedded into an external LMS using Remote SCORM, the following domains are also required:
masterplan-lms.com
app.masterplan-lms.com
api.masterplan-lms.comOptional Services
The following services enhance the user experience but are not required for the core functionality of Masterplan.
Blocking these services does not prevent users from logging in, playing videos, or tracking learning progress.
Notifications
api.knock.app(WebSocket connections may also be used.)
In-App Guidance
*.userpilot.ioSupport Chat
*.zendesk.com
*.zopim.com
*.zdassets.com(WebSocket connections may also be used.)
Diagnostics & Monitoring
*.logrocket.io
*.logrocket.com
sentry.io
o74727.ingest.sentry.io
*.nr-data.net
js-agent.newrelic.comNotes for IT Administrators
For organizations using strict firewalls, proxies, or TLS inspection, please consider the following technical requirements:
- HTTPS only over TCP port 443
- No UDP or QUIC traffic
- Minimum TLS version 1.2 (TLS 1.3 supported)
- TLS 1.0 and TLS 1.1 are not supported
- Allowlist hostnames instead of IP addresses, as these services are delivered through CDNs with changing IP ranges.
TLS Inspection
The web application does not use certificate pinning. Therefore, TLS interception ("break-and-inspect") proxies using an internal certificate authority are supported without additional configuration.
Video Playback
Masterplan streams videos using:
- HLS (.m3u8)
- H.264 video
- AAC audio
- Fragmented MP4 segments
No DRM technologies (Widevine, PlayReady, or FairPlay) are used.
Video access is protected through signed authentication tokens, so allowing the video hostname alone does not expose any content.
If your security infrastructure performs deep inspection of video traffic, playback interruptions may occur due to increased latency. In this case, we recommend exempting the following hostname from deep content inspection while still allowing TLS termination and policy enforcement:
customer-qqv9dy4gjtd32v0z.cloudflarestream.comSystem Emails
To ensure invitation emails and platform notifications are delivered successfully, we recommend allowlisting the following sender information.
Sending Domain
mail.masterplan.comDedicated Sending IP
161.38.205.62