Overview
The Mind & Motion and First Resort applications require access to specific network URLs to function properly.
In restricted or private networks (such as clinics, hospitals, corporate environments, or networks with strict firewall or proxy policies), blocking these URLs may cause connectivity or functionality issues.
This article provides a list of required URLs to help IT teams and network administrators identify and whitelist the necessary endpoints.
When is this relevant?
This information is relevant if users experience any of the following issues:
- The application does not load or gets stuck during startup
- Sessions fail to start or end properly
- Content does not load or update
These issues often occur when required domains are blocked by firewalls, VPNs, or network security policies.
Required URLs – Mind & Motion
Ensure the following URLs are allowed and not blocked:
https://prod-realizedcare-vrxflex.xr.health/api/Flex/
https://prod-realizedcare-vrxflex.xr.health/api/RulesBlockGating/53/MM/2-0/{userId}/1/CST
https://prod-realizedcare-monolith.xr.health/api/User/Onboarding/xrhealth
https://prod-realizedcare-monolith.xr.health/api/User/Onboarding/securitycode/send
https://prod-realizedcare-monolith.xr.health/api/User/Onboarding/securitycode/verify
https://prod-realizedcare-monolith.xr.health/api/User/Onboarding/verify/phone/pin
https://prod-realizedcare-monolith.xr.health/api/User/Onboarding/applicationInstance/{applicationInstanceId}/practice/{practiceId}
https://prod-realizedcare-monolith.xr.health/api/device/{deviceName}/type/{terminalType}/sponsor/verify/application/{applicationId}
https://prod-realizedcare-monolith.xr.health/api/device/sponsor
https://prod-realizedcare-monolith.xr.health/api/device/sponsoronboarding
https://prod-realizedcare-monolith.xr.health/api/device/sponsor/complete
https://prod-realizedcare-monolith.xr.health/api/User/verify/terminal/pin
https://prod-platform.xr.health/api/vrapp/{deviceId}/configuration
https://prod-realizedcare-vrxflex.xr.health/api/RulesBlockGating/{vrxId}/{program}/{version}/{userId}/{blockId}/CST
https://prod-realizedcare-vrxflex.xr.health/api/RulesModuleGating/{vrxId}/{program}/{version}/{userId}/{blockId}/{timeZone}
https://prod-realizedcare-vrxflex.xr.health/api/Flex/User/{userId}/53/flex_category
https://prod-realizedcare-vrxflex.xr.health/api/Lookup/{dataType}/{key}
https://prod-realizedcare-workflow.xr.health/api/ContentModule/user/{userId}/experience/{experienceId}/contentmoduletype/{type}
https://prod-realizedcare-workflow.xr.health/api/eventmanagement/message
https://prod-realizedcare-workflow.xr.health/api/eventmanagement/events?userid={userId}&practiceID={practiceId}&vrxID={vrxId}
https://prod-platform.xr.health/api/vrapp/{deviceId}/session
https://behavr-<env>-svcs.eastus2.cloudapp.azure.com/dv/api/eventhub/createsastoken
Required URLs – First Resort
Ensure the following URLs are allowed and not blocked:
https://platform.xr.health/api/vrapp/eventmanagement/message
https://platform.xr.health/api/vrapp/eventmanagement/events?userid={userId}&practiceID={practiceId}&vrxID={vrxId}
https://platform.xr.health/api/vrapp/WorkflowSession/GetCurrentExperienceSessionForUser/{vrxId}/{userId}
https://platform.xr.health/api/vrapp/WorkflowSession/experience/{experienceId}/session/{experienceSessionId}/experiencesessiontype/{experienceSessionType}/end/instructionbucket
https://platform.xr.health/api/vrapp/WorkflowSession/experience/{experienceId}/session/{experienceSessionId}/experiencesessiontype/{experienceSessionType}/selfguided/gallery/instructionbucket
https://platform.xr.health/api/vrapp/WorkflowSession/GetExperienceSessionOutlineByExperienceSessionID/{experienceSessionId}
https://platform.xr.health/api/vrapp/WorkflowSession/createworkflowsessioninstance/
https://prod-realizedcare-monolith.xr.health/services.usersession/{userId}/values/experience/{experienceId}/limit/3
https://prod-realizedcare-monolith.xr.health/services.usersession/values/experience/{experienceId}
https://prod-realizedcare-monolith.xr.health/services.usersession/longtermgoals/experience/{experienceId}/values?value={valueId}
https://prod-realizedcare-monolith.xr.health/services.usersession/values
https://prod-realizedcare-monolith.xr.health/services.usersession/longtermgoals/complete
https://prod-realizedcare-monolith.xr.health/services.usersession/{userId}/shortTermGoal/complete
https://platform.xr.health/api/vrapp/ContentModule/user/{userId}/experience/{experienceId}/contentmoduletype/{contentModuleType}
https://platform.xr.health/api/vrapp/workflowsession/practice/{practiceId}/user/{userId}/thoughtlogs
https://prod-realizedcare-monolith.xr.health/api/User/Onboarding/securitycode/verify
https://prod-realizedcare-monolith.xr.health/api/User/Onboarding/securitycode/send
https://prod-realizedcare-monolith.xr.health/api/User/Onboarding/xrhealth
https://prod-realizedcare-monolith.xr.health/api/User/Onboarding/applicationInstance/{applicationInstanceId}/practice/{practiceId}
https://prod-realizedcare-vrxflex.xr.health/api/Lookup/{dataType}/{key}
https://prod-realizedcare-vrxflex.xr.health/api/RulesBlockGating/{vrxId}/{program}/{version}/{userId}/{blockId}/{timeZone}
https://prod-realizedcare-vrxflex.xr.health/api/RulesModuleGating/{vrxId}/{program}/{version}/{userId}/{blockId}/{timeZone}
AI & voice features (First Resort)
If AI-based transcription or voice features are used, the following endpoints must also be accessible:
https://api.openai.com/v1/realtime/transcription_sessions wss://api.openai.com/v1/realtime?intent=transcription
Recommendations for IT teams
- Whitelist the domains listed above
- Allow HTTPS (TCP 443) and WebSocket (WSS) traffic
- Disable SSL inspection for these domains if possible
- Ensure outbound traffic is not blocked by firewall or proxy rules
Still having issues?
If connectivity issues persist after whitelisting the URLs:
- Verify the device is connected to the correct network
- Test the application on an unrestricted network (e.g., mobile hotspot)
- Contact XRHealth Support with details about the network environment
This will help us assist you more efficiently.