Allowed websites
Limit which websites can load your screens with your public keys.
By default, any website can use your public keys to load your published screens and send events. Allowed websites is an optional list that changes that. When you add at least one site, only listed sites can load your screens, and the rest get an error.
Use it when you want to stop someone from copying your public key into their own site and showing your screens, or inflating your view count.
Allowed websites need the Pro plan or above. You find the panel at the bottom of the API keys page.
How the check works
Browsers send an Origin header with cross-origin requests. Miniwall compares it with your list. If your list is not empty and the origin is not on it, the API answers 403 with origin_not_allowed and the message https://other.example is not in this project's allowed websites. Requests that carry no Origin header, such as direct server calls, are not blocked by this list. A public key is meant to be visible in your page, so treat the list as a guard against casual reuse, not as a secret.
Add a website
- Open API keys and find the Allowed websites panel.
- Type the address under Add a website. The field suggests
https://shop.example.com. - Select Add.
You may type the address with or without https://. Miniwall adds https:// when it is missing, makes it lowercase, and removes a trailing slash. A valid address is a scheme, a host and an optional port, with no path. If it is not valid, you see Enter a site address like https://shop.example.com (no path).
Adding an address that is already on the list does nothing.
Rules to remember
- Each subdomain is its own site.
https://shop.example.com,https://www.example.comandhttps://example.comare three entries. - Ports count. While you develop, add
http://localhost:3000or whichever port you use. - Scheme counts.
http://andhttps://are different entries. - The first entry blocks every other site. Before you add one, the panel warns: Once you add one, every site not on the list stops showing paywalls, so add all of them (each subdomain, and localhost while you develop).
- You can list up to 20 websites.
Remove a website
Select the x button on a row, labelled Remove followed by the address. The change applies at once. Removing the last site returns the project to Any website.
Removing sites is always allowed, even if your plan no longer includes allowed websites, so you can open a project back up after a downgrade.
What the panel shows
| State | Panel text |
|---|---|
| Empty list | Badge Any website. Any website can use your public keys. Add your domains to stop other sites from loading your paywalls. |
| One or more sites | A count such as 1 website or 3 websites. Only these websites can load paywalls with your public keys. Other sites get an error. |
| Plan does not include it | A lock badge with the plan name, and Allowed websites are on the Pro plan and above. with a See plans link. The input is disabled. |
| Views ran out and the grace ended | Allowed websites are paused: this month's views ran out. Removing sites still works. |
Who can do what
Adding and removing sites needs the Admin role or above. Others see a Needs Admin chip and the reason under the input.