Update security headers

<Info>This API is in beta. Endpoints, fields, and behavior may still change, so avoid depending on it in production.</Info>

Changes the app's security header settings and returns them as they now stand.

Send only the settings you want to change. A setting you leave out keeps its value.

A change applies to the published app right away, with no need to deploy it again. It doesn't affect the builder's preview.

Turning on a setting that Get security scan recommends in header_recommendations removes that recommendation from the scan result.

This is limited to 30 requests a minute per app for each workspace's personal API keys, so every key in a workspace shares one allowance. Some workspaces have a different limit.

<Note>This endpoint accepts a personal API key belonging to a user with editor access to the app. A read-only key is refused, and workspace API keys are not accepted.</Note>

put/api/apps/{app_id}/security/headers

Path parameters

app_idstring required

ID of the app.

ID of the app.

Request body

prevent_iframe_embeddingboolean

Set true to stop every site from showing the published app in a frame. Set false to lift that block, so framing follows the app's other settings and its workspace's policy again.

restrict_browser_featuresboolean

Set true to make the published app send a restrictive Permissions-Policy header, or false to stop sending it.

Example request

{
  "prevent_iframe_embedding": true,
  "restrict_browser_features": true
}

Response

The app's security header settings after the change.

Example response

{
  "result": {
    "embedding_origins": [
      "https://partners.acme.com"
    ],
    "org_embedding_origins": [
      "https://partners.acme.com"
    ],
    "app_policy": {
      "mode": "allowlist",
      "origins": [
        "https://partners.acme.com"
      ]
    },
    "effective_policy": {
      "mode": "allowlist",
      "source": "app",
      "origins": [
        "https://partners.acme.com"
      ]
    }
  }
}

Changes

Changed in 1 of the 22 revisions of this API.1

Of the 22 revisions, 1 has no diff computed.