Allowed sites and CSP
The editor only appears on sites you list. Anywhere else the browser refuses to show it — so someone who copies your publishable key onto their own site gets nothing.
Adding your sites
lettrove.com → Settings → Embed → your project → Sites. Type the address and choose its list:
| List | Opens with | Add |
|---|---|---|
| Test | Test keys | Your staging sites, e.g. https://staging.acme.com. localhost (any port) is allowed for test keys without adding it. |
| Live | Live keys | Your production sites, e.g. https://app.acme.com. Only https, never localhost. |
Write a site as its origin: the scheme and host, and the port if it has one —
https://app.acme.com, not https://app.acme.com/editor. A full address you paste is reduced to
its origin.
A change applies within about a minute.
How it is checked
Two things must agree before the editor opens:
- The site showing the editor is on the project's list for the publishable key's environment. The browser enforces this: the editor's page tells it which sites may frame it.
- The token was minted for that site (
originintokens.create). A token minted for another site is refused, so a token copied from one site does not work on another.
If either does not, the editor's box says which, with a code: origin_not_allowed, or
frame_blocked when the browser refused to show it.
Content-Security-Policy
If your pages send a Content-Security-Policy header, it must allow the editor's frame:
Content-Security-Policy: frame-src https://lettrove-embed.com
Add https://lettrove-embed.com to your existing frame-src (or child-src) list. With the script-tag
install, also allow the script's host in script-src:
script-src 'self' https://cdn.jsdelivr.net
Nothing else is needed: the editor talks only to its own site, from inside its frame, so your
connect-src does not change.
When a policy blocks the editor, the box says frame_blocked and names this rule.