Update security headers
<Info>This API is in beta. Endpoints, fields, and behavior may still change, so avoid depending on it in production.</Info>
Changes the app's security header settings and returns them as they now stand.
Send only the settings you want to change. A setting you leave out keeps its value.
A change applies to the published app right away, with no need to deploy it again. It doesn't affect the builder's preview.
Turning on a setting that Get security scan recommends in header_recommendations removes that recommendation from the scan result.
This is limited to 30 requests a minute per app for each workspace's personal API keys, so every key in a workspace shares one allowance. Some workspaces have a different limit.
<Note>This endpoint accepts a personal API key belonging to a user with editor access to the app. A read-only key is refused, and workspace API keys are not accepted.</Note>
Path parameters
ID of the app.
ID of the app.
Request body
Example request
{
"prevent_iframe_embedding": true,
"restrict_browser_features": true
}Response
The app's security header settings after the change.
Example response
{
"result": {
"embedding_origins": [
"https://partners.acme.com"
],
"org_embedding_origins": [
"https://partners.acme.com"
],
"app_policy": {
"mode": "allowlist",
"origins": [
"https://partners.acme.com"
]
},
"effective_policy": {
"mode": "allowlist",
"source": "app",
"origins": [
"https://partners.acme.com"
]
}
}
}Changes
Changed in 1 of the 33 revisions of this API.1
- ○
endpoint added
endpoint-added
- ○