Miniwall Docs
Web SDK

Security and CSP

What the SDK does to stay safe on your page, which Content Security Policy rules it needs, and how allowed websites work.

Public key

The key that starts with pk_ can read published screens and send events. It cannot edit anything and is safe in your page. To stop other sites from using it, add your domains to Allowed websites (Pro plan and above, see Allowed domains).

  • With a list set, a request whose Origin is not on it gets 403 origin_not_allowed. Add every site, each subdomain, and localhost while you develop.
  • With no list, any website can use the key.

What the SDK protects

  • The screen draws in a shadow root. Your CSS cannot break it and its CSS cannot leak out.
  • Screen text is escaped before its markdown becomes HTML. customVariables values show as plain text, never HTML.
  • Only http, https, mailto, tel and links starting with a single / are opened or handed to onOpenUrl. A javascript: or data: link is refused and reported to onError.
  • Custom fonts load only from https URLs.
  • Analytics requests use text/plain posts with no cookies and no credentials.

Content Security Policy

If your site sets a CSP, allow:

DirectiveValueWhy
script-srcWhere you load the SDK from: your bundle, or the host of the script URLThe SDK code.
style-src'unsafe-inline'The SDK injects styles into the screen's shadow root and onto the page for overlays.
connect-srchttps://json-ui-kit-api.vercel.app, or your apiUrlDelivery and events.
font-srchttps://cdn.jsdelivr.netFonts picked in the editor load from Fontsource on jsDelivr.
img-srcWhere the screen's images live (Miniwall image storage, or your own URLs)Images.

On this page