Security
Allowed origins
Verity only accepts widget traffic from origins you explicitly approve. This keeps your publishable keys from being reused on unknown domains.
Rules
- • Origins must match exactly (scheme + host + port).
- • Add each environment (prod, staging) separately.
- • A wildcard entry
*is supported, and will allow any origin (use with care).
Examples
✅ https://app.example.com
✅ https://staging.example.com
❌ http://app.example.com (wrong scheme)
