Security and privacy
Content Security Policy
The directives your CSP needs for the PlayStep web SDK.
The SDK uses no eval and no inline scripts, and draws its UI in a shadow root with its own stylesheet. If your site sends a Content-Security-Policy, allow:
script-src https://cdn.playstep.app
connect-src https://cdn.playstep.app https://api.playstep.app
media-src https://clips.playstep.app
img-src https://clips.playstep.app https://i.ytimg.com
style-src 'unsafe-inline'
style-src 'unsafe-inline'is for the stylesheet inside the shadow root. If your policy cannot allow it, contact us for a nonce-based build.- Add your own hosts to
media-srcandimg-srcif you use external clips. - For YouTube and Vimeo embeds, add
frame-src https://www.youtube-nocookie.com https://player.vimeo.com. - With
@playstep/webfrom npm,script-srcneeds only your own origin.