The Security & domains tab lets you control which domains are allowed to embed your Hosted Customer Flows widgets (checkout, sign-up, and account management). This prevents your widgets from being loaded on unauthorized or spoofed pages.
Where to find it
In the Cleeng Dasboard go to Admin & Tools > Hosted Customer Flows > Security.
How it works
When you turn the domain restriction toggle On and add one or more domains to your allowlist, your widgets will only load on those domains. If a site that is not on the list tries to embed a widget, the browser blocks it (cross-origin) and the widget does not render.
Managing allowed domains
You can add and remove domains at any time. Changes take effect immediately.
- To add a domain, enter it in the field (for example,
yourdomain.com) and click Add domain. - To allow an entire set of subdomains, use a wildcard (for example,
*.subdomain.com). - To remove a domain, click the trash icon next to it.
What your customers see
If a widget is loaded on a domain that is not allowlisted, it will not render. Customers on that page see an "Invalid origin" message instead.
Related articles
MediaStore Hosted Customer Flows