10-09-2018 10:34
- Mark as New
- Bookmark
- Subscribe
- Permalink
- Report this post

10-09-2018 10:34
- Mark as New
- Bookmark
- Subscribe
- Permalink
- Report this post
Hey all,
I work for a healthcare organization and we are trying to sync Fitbit data back into our Epic EMR environment. Using a reverse proxy server endpoint to send the traffic through we are running into issues figuring out what to "whitelist." I have seen the documentation stating not to whitelist but does anyone know if all the traffic is at least coming from api.fitbit.com? Thanks for your time.

10-29-2018 14:25
- Mark as New
- Bookmark
- Subscribe
- Permalink
- Report this post



10-29-2018 14:25
- Mark as New
- Bookmark
- Subscribe
- Permalink
- Report this post
Hi @Telehealthynhh,
You are correct, you should not whitelist the Fitbit IP addresses for your subscriber endpoints. Instead, you should verify the X-fitbit-Signature header in the requests. The data should be coming from a fitbit.com server.
Please read the Security section of the documentation for more information.
Gordon
Senior Technical Solutions Consultant
Fitbit Partner Engineering & Web API Support | Google

