Skip to content

Allowed origins ​

Add each site that runs the SDK in Settings → Developers → Domains & CORS. Use the full origin: scheme, host and port when needed.

text
https://www.example.com
https://app.example.com
http://localhost:3000

If you forget a site, the browser blocks the SDK's requests and shows a CORS error in the console.

The allow-list is not authentication

It only restricts browsers. A script outside a browser can send any Origin header. Treat the public key as public, and use identity verification to protect identities.

JustOneCX