Content-Security-Policy header, it has to permit what the widget loads. This page lists the directives derived from the SDK and from the policy Fanfare-hosted pages send, and marks separately the ones that come from Stripe’s own guidance and still need confirming against a live checkout.
The Fanfare-hosted policy
Fanfare-hosted experience pages send this policy. It is the closest thing to a reference implementation: it is strict, it is the one Fanfare runs, and every origin in it is one the widget genuinely needs.What each origin is for
Stripe. Fanfare-managed checkout collects the card in your document, so Stripe’s own runtime has to load: Stripe.js comes fromjs.stripe.com, the card field and its per-request frames come from *.js.stripe.com, the 3-D Secure challenge is a frame on hooks.stripe.com, and the client calls api.stripe.com. Stripe Hosted Checkout, Connect embedded components, and the Address Element’s Maps origins are not loaded, so they need no allowance.
Your Fanfare origins. connect-src must allow the consumer API origin and the beacon origin your integration is configured with. These are your own values — the hosted policy interpolates them rather than hard-coding them.
style-src 'unsafe-inline'. The widget’s motion animations render inline style attributes and inject <style> elements. CSP offers no nonce or hash path that covers dynamic style attributes, so this relaxation is required. It is scoped to styles only: script execution stays gated by script-src, which never carries 'unsafe-inline'.
Fonts
The font origins are needed only whenloadFonts is on. If you load your fonts yourself, or self-host them, allow your own origins instead and skip these.
See Fonts for what
loadFonts requests and when.
To verify
These are not derivable from the SDK, which names only Stripe’s script URL. They come from Stripe’s published CSP guidance and should be confirmed against a real checkout before you rely on them:frame-srcfor any Stripe runtime frame beyond those listed above.connect-srcfor any Stripe endpoint beyondapi.stripe.com.- Any Stripe fraud-signal host, such as
m.stripe.network.