Get security headers

Changed on

<Info>This API is in beta. Endpoints, fields, and behavior may still change, so avoid depending on it in production.</Info>

Returns the app's security header settings, and the framing policy the published app follows once its workspace's policy is applied.

Change prevent_iframe_embedding and restrict_browser_features with Update security headers. effective_policy is what the published app actually enforces, so read it rather than working the policy out from the other fields. When app_allowlist_locked_by_workspace is true, the workspace's policy decides who can frame the app.

This is limited to 60 requests per minute per app for each workspace's personal API keys, so every key in a workspace shares one allowance. Some workspaces have a different limit.

<Note>This endpoint accepts a personal API key belonging to a user with editor access to the app. A read-only key is refused, and workspace API keys are not accepted.</Note>

get/api/apps/{app_id}/security/headers

Request

  • Base URL: https://app.base44.com
  • URL: https://app.base44.com/api/apps/{app_id}/security/headers
  • Auth: HTTP bearer

Path parameters

app_idstring required

ID of the app.

Response

The app's security header settings.

Example response

{
  "result": {
    "embedding_origins": [
      "https://partners.acme.com"
    ],
    "org_embedding_origins": [
      "https://partners.acme.com"
    ],
    "app_policy": {
      "mode": "allowlist",
      "origins": [
        "https://partners.acme.com"
      ]
    },
    "effective_policy": {
      "mode": "allowlist",
      "source": "app",
      "origins": [
        "https://partners.acme.com"
      ]
    }
  }
}

Changes