Content Security Policy for widget installation
Understand which browser security directives can affect ShopFlare embeds and how to make narrowly scoped policy changes.
Keep your existing policy
The installation area provides guidance for the domains used by your widget. Merge the necessary sources into your site's policy; do not replace a production policy with a generic example or disable it to fix a widget.
Check the relevant directives
The loader, embedded frame, and HTTPS requests have different requirements.
- script-src: permit the generated loader origin.
- frame-src: permit the widget frame origin.
- connect-src: permit the configured HTTPS API and site origins.
- img-src, style-src, and font-src: review the assets and fonts actually used.
Diagnose the precise block
Read the browser console to identify the directive and URL that were rejected. Share a redacted error with your technical contact. The standard chat connection uses HTTPS streaming rather than requiring a separate WebSocket host. Browser extensions and network filtering may cause similar symptoms.
Dashboard labels may currently be in German. Available controls and modules depend on your package and release. If a control described here is missing, check your workspace or contact support.
Still need a hand?
Tell us what you’re trying to do. Please leave out passwords and personal customer data.