Content Security Policy

The exact CSP directives to allow Benson's script and API hosts, matching what the setup scan recommends.

Reference
Updated 26 September 20261 min

If your store sends a Content-Security-Policy header, the browser will block Benson until you allow two hosts:

  • Script host: https://cdn.trybenson.com
  • API host: https://api.trybenson.com

The directives#

Add these sources to your existing policy (don't replace it):

script-src https://cdn.trybenson.com;
connect-src https://api.trybenson.com;
  • script-src lets the browser load the Benson loader and its modules.
  • connect-src lets it fetch your site's configuration and send events.

If your policy has no script-src or connect-src, the sources go into default-src instead. These are the same directives the setup wizard's scan recommends for your store.

What you don't need#

  • No unsafe-inline or unsafe-eval: Benson loads as an external script and never evaluates strings.
  • No frame-src: the widget renders in a shadow root on your page, not an iframe.
  • No img-src or font-src entries: the widget uses your store's fonts.

Report-only policies#

Content-Security-Policy-Report-Only doesn't block anything, so Benson works regardless. Add the directives anyway before you switch to enforcing.

Checking#

Open your store with ?benson_debug=1 and look for CSP violations in the console. The setup wizard also flags a blocking policy when it scans your store.

Stuck? Email [email protected].

Find out what's leaking. 14 days of Own, no card.