'self' stands in for whatever your policy already allows):
*.gleap.io covers the EU data region and the global hosts that every region uses (SDK, messenger app, static assets). *.gleap.ai covers the US data region (api.us.gleap.ai, ws.us.gleap.ai, sockets.us.gleap.ai, …); a CSP host wildcard matches subdomains at any depth. We recommend allowing both, regardless of your region. US projects always need both.We strongly recommend using the
https://*.gleap.io, https://*.gleap.ai, wss://*.gleap.io and wss://*.gleap.ai wildcards. The SDK contacts several Gleap subdomains (api.gleap.io, ws.gleap.io, sockets.gleap.io, messenger-app.gleap.io, outboundmedia.gleap.io, app.gleap.io, js.gleap.io; in the US region api.us.gleap.ai, ws.us.gleap.ai and sockets.us.gleap.ai take the place of the first three), and the list may grow as we ship new features. Note that the https:// wildcards do not cover WebSocket connections — wss:// origins must be allowed separately.WebSockets in connect-src
Gleap uses two WebSocket endpoints, and both must be allowed:
wss://ws.gleap.io(US region:wss://ws.us.gleap.ai) — session and event streaming used by the JavaScript SDK.wss://sockets.gleap.io(US region:wss://sockets.us.gleap.ai) — realtime delivery of conversations and notifications in the messenger.
wss://*.gleap.io and wss://*.gleap.ai.
Gleap previously relied on Pusher for realtime messaging, which required
*.pusher.com entries in connect-src. Realtime traffic now runs entirely on Gleap infrastructure (wss://sockets.gleap.io, or wss://sockets.us.gleap.ai in the US region), so any https://*.pusher.com or wss://*.pusher.com entries you added for Gleap can be removed.