Get security headers
Changed on<Info>This API is in beta. Endpoints, fields, and behavior may still change, so avoid depending on it in production.</Info>
Returns the app's security header settings, and the framing policy the published app follows once its workspace's policy is applied.
Change prevent_iframe_embedding and restrict_browser_features with Update security headers. effective_policy is what the published app actually enforces, so read it rather than working the policy out from the other fields. When app_allowlist_locked_by_workspace is true, the workspace's policy decides who can frame the app.
This is limited to 60 requests per minute per app for each workspace's personal API keys, so every key in a workspace shares one allowance. Some workspaces have a different limit.
<Note>This endpoint accepts a personal API key belonging to a user with editor access to the app. A read-only key is refused, and workspace API keys are not accepted.</Note>
Request
- Base URL: https://app.base44.com
- URL: https://app.base44.com/api/apps/{app_id}/security/headers
- Auth: HTTP bearer
Path parameters
ID of the app.
Response
The app's security header settings.
Example response
{
"result": {
"embedding_origins": [
"https://partners.acme.com"
],
"org_embedding_origins": [
"https://partners.acme.com"
],
"app_policy": {
"mode": "allowlist",
"origins": [
"https://partners.acme.com"
]
},
"effective_policy": {
"mode": "allowlist",
"source": "app",
"origins": [
"https://partners.acme.com"
]
}
}
}Changes
- ○
endpoint added
- ○