Content Security Policy
The exact CSP directives to allow Benson's script and API hosts, matching what the setup scan recommends.
If your store sends a Content-Security-Policy header, the browser will block Benson until you allow two hosts:
- Script host:
https://cdn.trybenson.com - API host:
https://api.trybenson.com
The directives#
Add these sources to your existing policy (don't replace it):
script-src https://cdn.trybenson.com;
connect-src https://api.trybenson.com;
script-srclets the browser load the Benson loader and its modules.connect-srclets it fetch your site's configuration and send events.
If your policy has no script-src or connect-src, the sources go into default-src instead. These are the same directives the setup wizard's scan recommends for your store.
What you don't need#
- No
unsafe-inlineorunsafe-eval: Benson loads as an external script and never evaluates strings. - No
frame-src: the widget renders in a shadow root on your page, not an iframe. - No
img-srcorfont-srcentries: the widget uses your store's fonts.
Report-only policies#
Content-Security-Policy-Report-Only doesn't block anything, so Benson works regardless. Add the directives anyway before you switch to enforcing.
Checking#
Open your store with ?benson_debug=1 and look for CSP violations in the console. The setup wizard also flags a blocking policy when it scans your store.
Stuck? Email [email protected].

