Skip to main content
If Granola works on one network but not another, or stops working when your company VPN, proxy, firewall, or web filtering software is enabled, the issue may be network filtering rather than audio permissions or app settings.

Run the network check

Open Settings > Troubleshooting in the Granola app.
  1. Select Run check under Network connectivity.
  2. Review the results. If anything needs attention, Granola shows which features were affected.
  3. Follow the Troubleshooting steps shown in the app. Granola asks whether you or IT manages the device or network, then suggests steps matched to your situation.
  4. Select Copy report to copy the full result for your IT team or Granola Support. On a work-managed device or network, you can also use Copy IT request to share a ready-made message for IT.
If several Granola services fail at once, check Granola service status before changing network settings.

Signs of a network problem

Network filtering can cause:
  • Sign-in loops, stalls, or never returning to Granola
  • Transcription that does not start, disconnects, or repeatedly retries
  • Notes and shared links stuck loading
  • Failed updates or installer downloads
  • Problems on office Wi-Fi or VPN, while Granola works on another network
  • Granola still blocked on a personal network (device filtering software may be the cause)
  • Certificate or secure connection errors
  • Unexpected sign-in, warning, or captive portal pages

What to try

  1. Run the network check and follow the troubleshooting steps in the app.
  2. If you use a VPN, turn it off temporarily and run the check again if your organization allows this.
  3. Try Granola on a different network, such as home Wi-Fi, to see whether the problem follows the network or your device. Filtering software on your computer can block Granola even when you switch networks.
  4. Share the copied report or IT request with your IT team if the problem only happens on a managed network or device.

Other troubleshooting guides

For network administrators

Share this section with IT teams configuring firewalls, proxies, SSL inspection, or web filtering tools such as Zscaler. Granola uses secure HTTPS and WebSocket connections. Allow the domains below without rewriting or redirecting their responses. For ordinary HTTPS domains, TLS/SSL inspection may remain enabled if managed devices trust the inspection certificate authority and the proxy passes requests and responses unchanged. stream.api.granola.ai must deliver response bodies incrementally. Disable response buffering and content scanning for this host. Exclude it from TLS inspection if your security product cannot inspect it without buffering the response. Transcription requires outbound secure WebSockets over TCP 443. Allow WebSocket upgrades and long-lived connections. Granola may use a direct connection or the operating system’s proxy path.

Core Granola app access

App downloads and updates

Transcription

If your network security tool supports wildcard entries, allow *.assemblyai.com. Otherwise, allow each AssemblyAI hostname listed above.

Sign-in, SSO, and calendar sync

Notifications

Allow both HTTPS and secure WebSocket traffic for real-time notifications.

Documentation and help center

Diagnostics and support logs

DNS CNAME targets for SASE and advanced DNS filtering

Common fixes for filtered networks

  1. Allow secure WebSocket traffic over TCP 443 to the transcription hosts.
  2. Disable response buffering for stream.api.granola.ai.
  3. Check that your security product does not replace responses with a warning or sign-in page.
  4. Test DNS resolution with the managed resolver.
  5. Make sure managed devices trust your TLS inspection certificate authority. Otherwise, exclude the affected Granola domains from inspection.