Appearance
Allowed origins
Add each site that runs the SDK in Settings → Developers → Domains & CORS. Use the full origin: scheme, host and port when needed.
text
https://www.example.com
https://app.example.com
http://localhost:3000If you forget a site, the browser blocks the SDK's requests and shows a CORS error in the console.
The allow-list is not authentication
It only restricts browsers. A script outside a browser can send any Origin header. Treat the public key as public, and use identity verification to protect identities.