This guide lists the infrastructure and network requirements your Epicor Kinetic environment must meet before it can connect to Fluent.
Scope
This checklist is for your IT, network, and Epicor administration teams. It covers the technical readiness of the Epicor endpoint only.
Note: Epicor users, credentials, Company IDs, API keys, access scopes, and agent-specific permissions are configured later during onboarding and are intentionally not covered here.
Infrastructure requirements
1. Public REST API endpoint
The Epicor Kinetic REST API must be enabled and available through a stable base URL.
The endpoint must be reachable from Fluent over the public internet. It cannot require an interactive VPN, a browser session, or access to a private-only network.
Use HTTPS for production connections. A typical URL is https://yourcompany.epicorsaas.com.
Your web server, reverse proxy, firewall, and WAF must forward Epicor REST paths without redirecting requests to an interactive sign-in page.
Fluent can use Epicor REST API v1 or v2. The endpoint must allow the applicable API path:
REST API v1:
/api/v1/REST API v2:
/api/v2/odata/{companyId}/
2. DNS and port access
The hostname should resolve publicly to at least one IPv4 address through a DNS A record. A public IP address can be used directly, but a hostname is recommended for HTTPS certificate validation.
Fluent must be able to open a TCP connection to the port specified in the URL. This is normally port 443 for HTTPS.
If you use a custom port, include it in the Epicor base URL and allow traffic to that exact port.
3. Firewall and IP allowlisting
If your organization restricts inbound traffic, allow Fluent's outbound IP addresses to reach the Epicor endpoint and port:
3.147.233.1583.16.223.873.17.236.197
If your environment does not restrict inbound traffic by source IP, no allowlist change is required.
4. TLS and certificates
The endpoint must support TLS 1.2 or TLS 1.3.
The server certificate must be present and not expired.
A certificate issued by a trusted certificate authority is recommended. If certificate validation is enabled in Fluent, the certificate chain and hostname must validate successfully.
A self-signed certificate can only be used when certificate validation is disabled during connection setup.
Any firewall or proxy performing TLS inspection must pass the negotiated TLS session through to Epicor. Fluent supports a TLS 1.2 maximum for environments whose inspection tooling does not support TLS 1.3.
5. REST request compatibility
Your reverse proxy, firewall, or WAF must allow non-interactive server-to-server requests to Epicor.
Allow the HTTP methods required by your Fluent agents. The connection test uses POST, so the endpoint cannot be restricted to GET or browser traffic.
Do not strip standard Epicor request headers, including Authorization, CallSettings, Content-Type, Accept, and X-API-Key when REST API v2 is used.
Allow JSON request and response bodies.
What Fluent validates
During connection setup, Fluent performs these checks before saving the connection:
Validates the Epicor base URL
Resolves the hostname to an IPv4 address, unless the URL uses an IP address directly
Opens a TCP connection to the URL's configured port
Checks that an HTTPS endpoint returns a present, unexpired certificate
Sends an authenticated POST request to Epicor's Ice.Lib.SessionModSvc/Login operation using the connection details provided during onboarding
Next step
Once these infrastructure requirements are in place, continue with Fluent Technical Onboarding: Epicor to configure the Epicor integration user, API key, access scope, and Fluent connection.
If your IT or network team needs help confirming these requirements, contact support@fluenterp.com.
