> Lettrove docs 1.x · https://docs.lettrove.com/docs/editor/allowed-sites

# Allowed sites and CSP

The editor only appears on sites you list. Anywhere else the browser refuses to show it — so
someone who copies your publishable key onto their own site gets nothing.

## Adding your sites

lettrove.com → **Settings → Embed** → your project → **Sites**. Type the address and choose its list:

| List | Opens with | Add |
|---|---|---|
| **Test** | Test keys | Your staging sites, e.g. `https://staging.acme.com`. `localhost` (any port) is allowed for test keys without adding it. |
| **Live** | Live keys | Your production sites, e.g. `https://app.acme.com`. Only `https`, never `localhost`. |

Write a site as its **origin**: the scheme and host, and the port if it has one —
`https://app.acme.com`, not `https://app.acme.com/editor`. A full address you paste is reduced to
its origin.

A change applies within about a minute.

## How it is checked

Two things must agree before the editor opens:

1. The **site** showing the editor is on the project's list for the publishable key's environment.
   The browser enforces this: the editor's page tells it which sites may frame it.
2. The **token** was minted for that site (`origin` in `tokens.create`). A token minted for another
   site is refused, so a token copied from one site does not work on another.

If either does not, the editor's box says which, with a code: `origin_not_allowed`, or
`frame_blocked` when the browser refused to show it.

## Content-Security-Policy

If your pages send a `Content-Security-Policy` header, it must allow the editor's frame:

```text
Content-Security-Policy: frame-src https://lettrove-embed.com
```

Add `https://lettrove-embed.com` to your existing `frame-src` (or `child-src`) list. With the script-tag
install, also allow the script's host in `script-src`:

```text
script-src 'self' https://cdn.jsdelivr.net
```

Nothing else is needed: the editor talks only to its own site, from inside its frame, so your
`connect-src` does not change.

When a policy blocks the editor, the box says `frame_blocked` and names this rule.
