Skip to main content

Allowed sites and CSP

The editor only appears on sites you list. Anywhere else the browser refuses to show it — so someone who copies your publishable key onto their own site gets nothing.

Adding your sites​

lettrove.com → Settings → Embed → your project → Sites. Type the address and choose its list:

ListOpens withAdd
TestTest keysYour staging sites, e.g. https://staging.acme.com. localhost (any port) is allowed for test keys without adding it.
LiveLive keysYour production sites, e.g. https://app.acme.com. Only https, never localhost.

Write a site as its origin: the scheme and host, and the port if it has one — https://app.acme.com, not https://app.acme.com/editor. A full address you paste is reduced to its origin.

A change applies within about a minute.

How it is checked​

Two things must agree before the editor opens:

  1. The site showing the editor is on the project's list for the publishable key's environment. The browser enforces this: the editor's page tells it which sites may frame it.
  2. The token was minted for that site (origin in tokens.create). A token minted for another site is refused, so a token copied from one site does not work on another.

If either does not, the editor's box says which, with a code: origin_not_allowed, or frame_blocked when the browser refused to show it.

Content-Security-Policy​

If your pages send a Content-Security-Policy header, it must allow the editor's frame:

Content-Security-Policy: frame-src https://lettrove-embed.com

Add https://lettrove-embed.com to your existing frame-src (or child-src) list. With the script-tag install, also allow the script's host in script-src:

script-src 'self' https://cdn.jsdelivr.net

Nothing else is needed: the editor talks only to its own site, from inside its frame, so your connect-src does not change.

When a policy blocks the editor, the box says frame_blocked and names this rule.