Content Security Policy
Most websites don't need this page. If yours sets a Content Security Policy, add Corner's address to it so the messenger can load.
What it is
A Content Security Policy (CSP) is a security setting some websites send with every page. It lists the only addresses the page may load scripts, images and connections from. Anything not on the list is blocked, so the messenger silently never appears.
It can be set by your web server or hosting (a Content-Security-Policy header), by a security plugin, or in the page itself (a <meta http-equiv="Content-Security-Policy"> tag).
What to add
Add Corner's address to these three directives, keeping everything already there. If a directive isn't in your policy, add it to default-src instead or create it.
script-src: loads the messenger's script.connect-src: answers, live replies and file uploads.img-src: photos in the chat.blob:anddata:show photos a visitor attaches. If your messenger uses a logo from another address, add that address too.
Nothing is needed in style-src: the messenger keeps its styles to itself.
A full example
A simple policy with Corner added looks like this:
Special cases
- Safari versions before 16.4 also need
'unsafe-inline'instyle-src. Current browsers don't. - If your policy uses
'strict-dynamic', addresses inscript-srcare ignored. Give the Corner script tag your page's nonce instead:
Corner checks it for you
You don't have to read your own policy. The Install page in Corner checks your website automatically and tells you whether anything blocks the messenger. If something does, it shows the exact lines to add and your whole policy with Corner already in it, ready to copy. The Email it to your developer button includes these lines too.