Miniwall Docs
Dashboard

Allowed websites

Limit which websites can load your screens with your public keys.

By default, any website can use your public keys to load your published screens and send events. Allowed websites is an optional list that changes that. When you add at least one site, only listed sites can load your screens, and the rest get an error.

Use it when you want to stop someone from copying your public key into their own site and showing your screens, or inflating your view count.

Allowed websites need the Pro plan or above. You find the panel at the bottom of the API keys page.

How the check works

Browsers send an Origin header with cross-origin requests. Miniwall compares it with your list. If your list is not empty and the origin is not on it, the API answers 403 with origin_not_allowed and the message https://other.example is not in this project's allowed websites. Requests that carry no Origin header, such as direct server calls, are not blocked by this list. A public key is meant to be visible in your page, so treat the list as a guard against casual reuse, not as a secret.

Add a website

  1. Open API keys and find the Allowed websites panel.
  2. Type the address under Add a website. The field suggests https://shop.example.com.
  3. Select Add.

You may type the address with or without https://. Miniwall adds https:// when it is missing, makes it lowercase, and removes a trailing slash. A valid address is a scheme, a host and an optional port, with no path. If it is not valid, you see Enter a site address like https://shop.example.com (no path).

Adding an address that is already on the list does nothing.

Rules to remember

  • Each subdomain is its own site. https://shop.example.com, https://www.example.com and https://example.com are three entries.
  • Ports count. While you develop, add http://localhost:3000 or whichever port you use.
  • Scheme counts. http:// and https:// are different entries.
  • The first entry blocks every other site. Before you add one, the panel warns: Once you add one, every site not on the list stops showing paywalls, so add all of them (each subdomain, and localhost while you develop).
  • You can list up to 20 websites.

Remove a website

Select the x button on a row, labelled Remove followed by the address. The change applies at once. Removing the last site returns the project to Any website.

Removing sites is always allowed, even if your plan no longer includes allowed websites, so you can open a project back up after a downgrade.

What the panel shows

StatePanel text
Empty listBadge Any website. Any website can use your public keys. Add your domains to stop other sites from loading your paywalls.
One or more sitesA count such as 1 website or 3 websites. Only these websites can load paywalls with your public keys. Other sites get an error.
Plan does not include itA lock badge with the plan name, and Allowed websites are on the Pro plan and above. with a See plans link. The input is disabled.
Views ran out and the grace endedAllowed websites are paused: this month's views ran out. Removing sites still works.

Who can do what

Adding and removing sites needs the Admin role or above. Others see a Needs Admin chip and the reason under the input.

On this page