Overview
Active Learning Labs is a web application for career and technical education. Students and teachers use it in a browser on Chromebooks, Windows, macOS or iPad. Nothing is installed on the device, and all traffic uses HTTPS or secure WebSockets on TCP port 443.
Most districts need to do two things: allow the domains in the list below, and exclude the hosts marked for SSL inspection bypass from decryption. If your network already permits Google Workspace services (Google sign-in, Firebase, reCAPTCHA), you are most of the way there.
We cannot publish fixed IP addresses. The application and its content are served through Amazon CloudFront and Google Cloud, whose IP ranges change without notice. Please allowlist by hostname.
Allowlist
Paste this into your content filter or firewall. Securly, GoGuardian, Lightspeed, Linewize, iboss, Palo Alto and similar products all accept hostnames and wildcards. Apply it to both student and staff policies.
# Active Learning Labs (app, content, live class events) *.activelearninglabs.com # Sign-in, saved progress and live sync (Google / Firebase) accounts.google.com apis.google.com identitytoolkit.googleapis.com securetoken.googleapis.com firestore.googleapis.com *.firebaseio.com # Login protection (Google reCAPTCHA) www.google.com www.gstatic.com # Slide viewer engine cdn.jsdelivr.net # Embedded lesson videos (YouTube) www.youtube.com www.youtube-nocookie.com *.ytimg.com *.googlevideo.com # Optional: web fonts, teacher support chat, usage analytics fonts.googleapis.com fonts.gstatic.com *.tawk.to www.googletagmanager.com *.google-analytics.com
Wildcards are preferred where your filter supports them. If it does not, the table below lists the exact hosts observed.
Domain details
Hosts marked Required are needed for lessons to work. Optional hosts improve the experience but students can work without them. Bypass SSL marks hosts that should be excluded from HTTPS decryption. From vendor docs marks hosts taken from the provider's own documentation rather than observed in our network audit.
| Host | Used for | Status | Notes |
|---|---|---|---|
| Active Learning Labs | |||
| app.activelearninglabs.com | The application: pages, scripts, API, and all lesson content (PDF slides, images and uploaded media under /static-content/, delivered by Amazon CloudFront) | RequiredBypass SSL | Serves PDFs and images. Opening a lesson link directly may return the app with an HTTP 404 status; the lesson still loads, so do not block on status code. |
| ws.activelearninglabs.com | Live class events over a long-lived WebSocket (teacher controls, pacing, team activity) | RequiredBypass SSL | WebSocket (wss). Do not close idle connections during a class period. |
| www.activelearninglabs.com | Public website. Users land here after logging out | Optional | Not needed during lessons. |
| Sign-in, saved progress and live sync (Google / Firebase) | |||
| accounts.google.comapis.google.com | Google Identity Services and the Google API client, loaded on every page. Also handles Sign in with Google | Required | |
| identitytoolkit.googleapis.comsecuretoken.googleapis.com | Firebase Authentication: session token exchange after any login, and the hourly token refresh | Required | Without the token refresh host, sessions drop after about an hour. |
| firestore.googleapis.com | Firebase Firestore: saves student progress and streams updates over a long-lived channel | RequiredBypass SSL | Long-polling connections stay open for the whole lesson. |
| *.firebaseio.com | Firebase Realtime Database over WebSocket | RequiredBypass SSL | Connects to rotating shard hostnames such as s-gke-usc1-nssi4-29.firebaseio.com. Use the wildcard. |
| Login protection | |||
| www.google.comwww.gstatic.com | Google reCAPTCHA on the login page. Some sign-ins show an image challenge | Required | Blocking these blocks email and password sign-in. |
| Slide viewer | |||
| cdn.jsdelivr.net | Rendering engine for PDF slides (pdf.js worker script) | Required | Without it, slides do not render. |
| Embedded lesson videos | |||
| www.youtube.comwww.youtube-nocookie.com*.ytimg.com*.googlevideo.com | Some lessons embed YouTube videos. The player loads from youtube.com, thumbnails from ytimg.com and the video stream from googlevideo.com | RequiredFrom vendor docs | Only needed for lessons that contain video. Districts that use YouTube Restricted Mode can keep it on; our videos are not age-restricted. |
| Optional services | |||
| fonts.googleapis.comfonts.gstatic.com | Web fonts | Optional | Pages fall back to system fonts if blocked. |
| *.tawk.to | In-app support chat for teachers to reach us. Not loaded for student accounts | Optional | Uses WebSocket to rotating vsbNN.tawk.to servers. Recommended for staff policies. |
| www.googletagmanager.com*.google-analytics.comstats.g.doubleclick.net | Anonymous usage analytics | Optional | No effect on students if blocked. |
Hosts you may see in logs that need no action
Requests to csp.withgoogle.com are security-policy reports sent by Google's own sign-in frames. Chrome rejects them itself and they have no effect on the application. A country-specific Google domain such as www.google.com or www.google.co.uk may appear once at logout from the analytics library.
SSL inspection and decryption
Filters that decrypt HTTPS traffic (Securly, Lightspeed Filter, GoGuardian, Zscaler, Palo Alto and others) can alter binary responses and interrupt long-lived connections even when a host is allowed. Exclude these from decryption:
- app.activelearninglabs.com (PDF slides, images, fonts)
- ws.activelearninglabs.com (WebSocket)
- firestore.googleapis.com and *.firebaseio.com (long-lived sync)
- *.googlevideo.com (video streams, for lessons with video)
WebSocket upgrade: if your firewall or filter performs SSL inspection, it must also pass the WebSocket upgrade handshake (Connection: Upgrade, Upgrade: websocket) to ws.activelearninglabs.com and *.firebaseio.com. Some products decrypt the connection but then drop the upgrade. When that happens the lesson still loads and looks normal, but live class sync (teacher pacing, team activity) silently stops working. Most filters have a separate "allow WebSocket" or "bypass" setting for this.
Symptom to watch for: slides stuck on "Loading the document, please wait", or slides that load once after clearing the browser cache and then stop loading. In the cases we have investigated, the cause was a decrypting proxy or a cached response on a managed Chromebook, not the school's internet connection.
Ports, protocols and TLS
| Protocol | Port | Used by |
|---|---|---|
| HTTPS | TCP 443 | All application, API, content and video traffic |
| Secure WebSocket (wss) | TCP 443 |
|
| UDP | None | Not used |
- TLS 1.2 or later is required on every host. Proxies that negotiate TLS 1.0 or 1.1 will fail to connect, and the WebSocket in particular fails without an error message.
- WebSocket upgrade on port 443 must be permitted, including through any SSL-inspecting proxy (see the note above).
- Idle timeout of at least 60 minutes on WebSocket connections, so a connection opened at the start of a class period survives to the end.
Quick connectivity test
From a student device on the school network, open these in a browser tab. Each one should load without a warning or block page.
| Open this URL | What a pass looks like |
|---|---|
| https://app.activelearninglabs.com/ | The Active Learning Labs login page, including the reCAPTCHA badge in the lower right corner. No badge means www.google.com or www.gstatic.com is blocked. |
| https://app.activelearninglabs.com/static-content/network-check/sample-slide.pdf | A one-page PDF opens in the browser. A download prompt means the Chrome PDF viewer is disabled by policy; a block page means content delivery is filtered. |
To confirm the WebSocket, sign in with a test account on a device where DevTools is allowed, press F12, open the Network tab, choose the WS filter and reload. You should see a connection to ws.activelearninglabs.com with status 101 that stays open. If it shows a different status, or closes within a few seconds, the upgrade is being blocked.
Managed Chromebook policies
For devices managed in the Google Admin console (Devices, then Chrome, then Settings), apply these to the student and staff organizational units.
| Setting | Chrome policy | Value |
|---|---|---|
| Site allowed if you run a URL blocklist | URLAllowlist | If student Chrome policy blocks all sites by default (URLBlocklist contains *), add activelearninglabs.com, ws.activelearninglabs.com, google.com, googleapis.com, gstatic.com, firebaseio.com, cdn.jsdelivr.net and the YouTube hosts above. This policy is separate from your content filter. |
| Built-in PDF viewer stays enabled | AlwaysOpenPdfExternally | Disabled (false). Slides are PDFs rendered in the page. |
| Pop-ups allowed for the app | PopupsAllowedForUrls | https://app.activelearninglabs.com |
| Cookies allowed for the app | CookiesAllowedForUrls | https://app.activelearninglabs.com. If third-party cookies are blocked, also allow https://[*.]google.com so Google sign-in works. |
| JavaScript enabled | JavaScriptAllowedForUrls | https://app.activelearninglabs.com |
| PDF downloads not forced | DownloadRestrictions | Do not block or force-download PDF files. |
| Developer tools for troubleshooting | DeveloperToolsAvailability | Allowed on at least one admin or test device, so you can send us a Network panel screenshot. It can stay blocked for students. |
Chromebooks that use a Chrome extension filter (Securly, GoGuardian, Lightspeed) take the same host list from the Allowlist section through the extension's policy.
Email senders to allow
Teacher invitations, password resets, class codes and support replies come from our domain. Add it as a trusted sender in your mail filter so messages are not quarantined.
- *@activelearninglabs.com
Transactional email is delivered through SendGrid and is SPF and DKIM aligned with activelearninglabs.com. If your mail gateway filters by sending infrastructure rather than the From address, also allow sendgrid.net.
Sign-in
Email and password
The login form is protected by Google reCAPTCHA. The hosts www.google.com and www.gstatic.com must be reachable, or sign-in fails without a clear error.
Sign in with Google
Uses Google Identity Services (accounts.google.com). If your Google Workspace restricts which third-party apps may use Google sign-in, add Active Learning Labs to the trusted apps list. Contact support@activelearninglabs.com for the OAuth client ID.
Rostering
Teachers create classes and invite students with a class code or by email. No roster sync or LMS integration is required.
Supported browsers and devices
- Google Chrome, Microsoft Edge, Mozilla Firefox and Apple Safari: current version and one version back
- Chromebooks on a supported ChromeOS release
- iPad with Safari, landscape orientation recommended for worksheets
- A screen width of 1024 px or more is recommended for labs with spreadsheet worksheets
- No audio hardware required. Lessons with video include captions where available.
Troubleshooting: slides, images or video do not load
- Check the allowlistConfirm every Required host above is allowed for the student's policy, especially
app.activelearninglabs.comandcdn.jsdelivr.net. - Check SSL inspectionMake sure the hosts under SSL inspection are excluded from decryption. A slide that loads once after a cache clear and then stops is the classic sign of a decrypting proxy or a poisoned cached response.
- Test on a non-managed deviceTry the same lesson on a non-managed device on the school network, then on a managed device off the network. This separates filter problems from Chrome policy problems.
- Send us a Network panel screenshotOn a device where DevTools is allowed, press F12, open the Network tab, reload the activity, type
pdfin the filter box and screenshot the result. The status code tells us exactly where the request is being stopped. - Check video separatelyIf only videos fail, open
youtube.comdirectly on a student device. If it is blocked there, the lesson video will be blocked too. - Lesson loads but live sync does notIf students can open lessons but do not receive teacher pacing or team updates, the WebSocket is being blocked. Check the WS filter in DevTools as described in the connectivity test, and confirm your SSL inspection product passes the WebSocket upgrade to
ws.activelearninglabs.com.
Support: support@activelearninglabs.com. Include your district, the lab and activity name, the filtering product you use and the screenshot. We usually reply within one business day.
Privacy and security
Student data is stored in the United States on Amazon Web Services and Google Cloud. We collect only the data needed to run the classroom experience and never sell it or use it for advertising. Full details are in our Privacy Policy and our Data Security and Privacy Plan. A signed data privacy agreement for your district or state is available on request.
Change log
- 2026-10-01Page published. Every host was verified against a recorded student session through a complete lab. Lesson content moved behind
app.activelearninglabs.comand live class events moved tows.activelearninglabs.com, so no Amazon hostnames are required.
We give at least 30 days notice on this page before adding a new required host.
Questions about this page: support@activelearninglabs.com. Permanent link: www.activelearninglabs.com/it-admins
