Is your workstation Connect-ready?
Run a complete pre-flight check for Amazon Connect softphone agents. Validates new 2026 sign-in endpoints, WebRTC & ICE candidate types, Audio Enhancement eligibility, VDI detection, IPv6/dualstack S3, GovCloud FIPS, microphone, network performance, browser compatibility, and all AWS CCP endpoints — nothing uploaded, 100% client-side.
Amazon Connect Agent Workstation Validator — 2026 Edition
Amazon Connect's softphone uses WebRTC to deliver voice, chat, and omnichannel contacts directly through the browser. A correctly configured agent workstation is critical for call quality, agent availability, and customer satisfaction. This free tool validates every technical requirement — browser version, WebRTC ICE candidate types, NAT type detection, microphone access, STUN/TURN reachability, new 2026 sign-in endpoints (*.signin.aws), IPv6/dualstack S3 reachability, VDI environment detection, Audio Enhancement eligibility (noise suppression and voice isolation), omnichannel readiness, codec support, and network throughput — in a single click, with nothing uploaded. Updated for the mandatory October 2026 sign-in migration.
*.signin.aws and *.apps.signin.aws domains. All newly created instances use it by default from April 7 2026. Existing instances are automatically migrated on July 7 2026 if the new endpoints are reachable. All remaining instances are forcibly migrated by October 7 2026. Firewall teams must allowlist the new sign-in domains before these dates to prevent agent login failures. Password reset emails will now arrive from no-reply@signin.aws — ensure this is not blocked by your email security gateway.
*.my.connect.aws, *.awsapps.com, *.transport.connect.{region}.amazonaws.com, and the new sign-in domains *.signin.aws and *.apps.signin.aws. UDP 3478 is required outbound to TurnNlb-*.elb.{region}.amazonaws.com for STUN/TURN media. Stateless firewalls also need ephemeral UDP ports 32768–65535 open for RTP return traffic. For IPv6/dualstack S3 (required for new sign-in), allow *.s3.dualstack.{region}.amazonaws.com. Always use domain-based allowlisting — never IP ranges, as AWS IP ranges rotate without notice.
TurnNlb-*.elb.{region}.amazonaws.com, symmetric NAT forcing relay-only ICE candidates (detectable by this tool under the WebRTC check), a VPN in full-tunnel mode routing media through the VPN server and adding 100–200ms latency, or stateless firewall rules missing the ephemeral UDP port range for RTP return traffic. Run this validator and check the WebRTC ICE Candidate Types row — if you see relay-only candidates with no srflx, your NAT is symmetric and all media must traverse the TURN relay on UDP 3478.
VDIPlatform query parameter to the agent workspace URL: use ?VDIPlatform=CITRIX, ?VDIPlatform=AWS_WORKSPACE, or ?VDIPlatform=OMNISSA. This signals the CCP to perform WebRTC audio redirection. Citrix requires Workspace App 2305 or later on the local client. Without audio optimization, all RTP media processes on the VDI server, adding 50–200ms extra latency and degrading call quality significantly.
*.my.connect.aws, *.amazonaws.com, *.signin.aws, and the TurnNlb TURN server IP ranges. AWS publishes current IP ranges in ip-ranges.json under the AMAZON_CONNECT service tag.
ice_collection_timeout error means the Connect CCP could not gather ICE candidates within the timeout window — most commonly because UDP 3478 outbound traffic is blocked by a corporate firewall or NAT device. To diagnose: run this tool and check the WebRTC ICE check section. If you see zero srflx (server-reflexive) candidates, your firewall is blocking the STUN server on UDP 3478. Fix: allow outbound UDP 3478 to TurnNlb-*.elb.{region}.amazonaws.com and stun.l.google.com:19302. If using a stateless firewall, also open the ephemeral UDP port range (32768–65535) for RTP return traffic.
*.signin-fips.amazonaws-us-gov.com and *.apps.signin-fips.aws-us-gov.com. Select the us-gov-west-1 region in this tool's region dropdown and run the New Sign-in Migration check — it will specifically probe the GovCloud FIPS endpoints. All GovCloud instances must complete migration by October 7 2026. To test the new experience manually, append ?use-new-experience=true to your GovCloud Connect login URL.
More Free Online Tools
Simple tools. Surgical fixes. Zero friction.
Amazon Connect CCP Log Parser
Parse Amazon Connect CCP logs into structured, searchable diagnostics.
OpenAmazon Connect Agent Workstation Validator
Pre-flight check for Amazon Connect softphone agents.
OpenAmazon Connect Pricing Calculator
Instantly estimate monthly AWS Connect costs — voice, chat, email, campaigns, telephony & more.
OpenConnect CloudWatch Log Analyzer
Drop any Amazon Connect CloudWatch log and get a rich visual breakdown.
Open