> ## Documentation Index
> Fetch the complete documentation index at: https://docs.gleap.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Content Security Policy (CSP)

> Configure Content Security Policy for Gleap with the Gleap Ionic Capacitor SDK. Follow the integration code examples.

The Content-Security-Policy HTTP response header helps you reduce XSS risks on modern browsers by declaring which dynamic resources are allowed to load.

If you are making use of CSP, add the Gleap sources to the following directives. This is the complete allowlist — merge each line into the matching directive of your existing policy (`'self'` stands in for whatever your policy already allows):

```text theme={null}
script-src  'self' https://*.gleap.io https://*.gleap.ai;
style-src   'self' 'unsafe-inline' https://*.gleap.io https://*.gleap.ai;
font-src    'self' https://*.gleap.io https://*.gleap.ai data:;
connect-src 'self' https://*.gleap.io https://*.gleap.ai wss://*.gleap.io wss://*.gleap.ai;
frame-src   'self' https://*.gleap.io https://*.gleap.ai;
media-src   'self' https://*.gleap.io https://*.gleap.ai;
img-src     'self' https://*.gleap.io https://*.gleap.ai data: blob:;
```

<Info>
  `*.gleap.io` covers the EU [data region](/documentation/guides/data-regions) and the global hosts that every region uses (SDK, messenger app, static assets). `*.gleap.ai` covers the US data region (`api.us.gleap.ai`, `ws.us.gleap.ai`, `sockets.us.gleap.ai`, …); a CSP host wildcard matches subdomains at any depth. We recommend allowing both, regardless of your region. US projects always need both.
</Info>

<Warning>
  Installing the SDK from npm does **not** shrink this list. Gleap is effectively two apps: the SDK inside your app bundle, and the messenger app the SDK loads at runtime from `messenger-app.gleap.io`. Even though no Gleap `<script>` tag appears in your `index.html`, the messenger's script and stylesheet still load from a Gleap origin and are checked against your `script-src` and `style-src` — and the SDK's initial `fetch()` of the messenger document is checked against `connect-src`, even when the host is already allowed in `frame-src`. The `wss://` sources must be listed separately too, because the `https://` wildcard never matches WebSocket connections.
</Warning>

<Info>
  We strongly recommend using the `https://*.gleap.io`, `https://*.gleap.ai`, `wss://*.gleap.io` and `wss://*.gleap.ai` wildcards. The SDK contacts several Gleap subdomains (`api.gleap.io`, `ws.gleap.io`, `sockets.gleap.io`, `messenger-app.gleap.io`, `outboundmedia.gleap.io`, `app.gleap.io`, `js.gleap.io`; in the US region `api.us.gleap.ai`, `ws.us.gleap.ai` and `sockets.us.gleap.ai` take the place of the first three), and the list may grow as we ship new features. Note that the `https://` wildcards do **not** cover WebSocket connections — `wss://` origins must be allowed separately.
</Info>

### WebSockets in `connect-src`

Gleap uses two WebSocket endpoints, and both must be allowed:

* `wss://ws.gleap.io` (US region: `wss://ws.us.gleap.ai`) — session and event streaming used by the JavaScript SDK.
* `wss://sockets.gleap.io` (US region: `wss://sockets.us.gleap.ai`) — realtime delivery of conversations and notifications in the messenger.

If you'd rather not list them individually, allow `wss://*.gleap.io` and `wss://*.gleap.ai`.

<Note>
  Gleap previously relied on [Pusher](https://pusher.com) for realtime messaging, which required `*.pusher.com` entries in `connect-src`. Realtime traffic now runs entirely on Gleap infrastructure (`wss://sockets.gleap.io`, or `wss://sockets.us.gleap.ai` in the US region), so any `https://*.pusher.com` or `wss://*.pusher.com` entries you added for Gleap can be removed.
</Note>

### Strict CSPs without wildcards

If your security policy forbids wildcards, here is the full explicit allowlist the SDK uses today:

```javascript theme={null}
// All regions
https://js.gleap.io
https://app.gleap.io
https://app.gleap.ai
https://messenger-app.gleap.io
https://outboundmedia.gleap.io

// EU region (default)
https://api.gleap.io
wss://ws.gleap.io
wss://sockets.gleap.io

// US region
https://api.us.gleap.ai
wss://ws.us.gleap.ai
wss://sockets.us.gleap.ai
```

<Warning>
  This explicit list can change without notice as we add features or migrate infrastructure. The `https://*.gleap.io`, `https://*.gleap.ai`, `wss://*.gleap.io` and `wss://*.gleap.ai` wildcards are the safest choice.
</Warning>

Depending on your setup you might need to do some further customizations. Please check the browser console for any CSP errors and add the reported origins to the matching directive.
