IT setup for Mokxi
What a school network and a Google Workspace domain need to let Mokxi through. Nothing to install on any machine.
Last updated September 27, 2026.
Mokxi is a web page. The simulator and the compiler run in the browser on the student’s own machine, so it works on Chromebooks, Windows, macOS and Linux with no extension, plug-in or driver. What IT may need to do is below. What Mokxi does with student data is on the student data privacy page.
1. Domains to allow
Allow these in your web filter (GoGuardian, Securly, Lightspeed, Cisco Umbrella, a firewall allow list or similar). Mokxi does not work without them.
| Domain | What it is for |
|---|---|
| mokxi.com | The site, the editor, the lessons, the class pages and the API. Allow secure WebSockets (wss://mokxi.com) too: live collaboration rooms use them. |
| challenges.cloudflare.com | The bot check on the email sign-up and sign-in link forms. |
The first time a student builds code, their browser downloads the compiler from mokxi.com/toolchain/, about 70 MB, and keeps it for next time. If your filter caps download sizes or inspects large files, let that path through. If your filter decrypts HTTPS, make sure it still passes WebSocket upgrades to mokxi.com, or live collaboration rooms will not connect (everything else still works).
2. If students sign in with Google
| Domain | What it is for |
|---|---|
| accounts.google.com | Sign in with Google. |
| lh3.googleusercontent.com | The profile picture on a Google account, shown on the roster. |
3. If a teacher pays by card
| Domain | What it is for |
|---|---|
| checkout.stripe.com | Paying for the Classroom plan by card. |
| billing.stripe.com | Invoices, receipts and changing the card. |
4. Not needed
Mokxi works with all of these blocked.
| Domain | What it is for |
|---|---|
| github.com, avatars.githubusercontent.com | Sign in with GitHub. Students do not need it. |
| www.googletagmanager.com, *.google-analytics.com | Analytics on our marketing pages. Never loaded for a student in a class; safe to block. |
| connect.facebook.net, www.facebook.com | Ad measurement on our marketing pages. Never loaded for a student in a class; safe to block. |
5. Email
Sign-in links, address verification and support replies come from noreply@mail.mokxi.com and support@mail.mokxi.com, sent through our mail provider, Resend. Allow the sender domain mail.mokxi.com, or students signing in by email will wait for a link that never arrives. Every link in our email points to mokxi.com, and there is no tracking pixel in any of it.
6. Google Workspace for Education: students under 18
Google blocks users your domain marks as under 18 from signing in to any third-party app an administrator has not configured. Mokxi is one of those apps, so until you allow it, students will see “Access blocked” when they choose Sign in with Google. A super administrator does this once:
- Sign in to the Google Admin console (admin.google.com).
- Go to Security, then Access and data control, then API controls.
- Under App access control, choose Manage Third-Party App Access, then Add app, then OAuth App Name Or Client ID.
- Search for Mokxi’s client ID, below, and select the app it finds.
- Choose who it applies to: the whole domain, or the organisational units or groups your students are in.
- Set access to Trusted (or Limited, which is enough, since Mokxi asks only for the basic sign-in scopes) and finish.
The client ID could not be loaded just now. Reload the page, or ask us at privacy@mokxi.com.
Mokxi asks Google for openid, email and profile and nothing else: the student’s account id, name, email address and picture. It never asks for Drive, Gmail, Calendar or Classroom. Google’s own help article on this is “Control which third-party & internal apps access Google Workspace data”.
If you would rather not configure Google at all, students can sign in with an email link instead, which needs only the email setting above.
7. An email to forward to IT
For teachers: copy this to your IT team as it is. It has everything above in it.
Hello, I would like to use Mokxi (https://mokxi.com), a browser-based electronics and Arduino simulator, with my class. It runs in the browser with nothing to install. Could you make sure the following works on the school network and devices? Please allow these domains in the web filter (GoGuardian, Securly, Lightspeed or similar): mokxi.com (including secure WebSockets, wss://mokxi.com) challenges.cloudflare.com accounts.google.com and lh3.googleusercontent.com (if students sign in with Google) The first time a student builds code, the browser downloads the compiler from mokxi.com/toolchain/ (about 70 MB, cached after that). Please let it through any download size limit. Please allow email from mail.mokxi.com, so sign-in links reach students. Students can sign in with an email link; Google sign-in is not needed. Student data privacy: https://mokxi.com/privacy/students Full IT setup: https://mokxi.com/schools/it Thank you.
8. Questions
Email privacy@mokxi.com or use the support page. A person answers. For a data privacy agreement or a security questionnaire, see student data privacy.