Top

Documentation Index

Fetch the complete documentation index at: https://support.whatfix.com/llms.txt

Use this file to discover all available pages before exploring further.

What are the trusted Whatfix domains to whitelist?

Prev Next

If your organization uses a firewall to restrict network access to only specific websites or software, whitelist the following domains to ensure that your app can communicate with Whatfix and fetch content for your end users to view.

If your organization has a Content Security Policy (CSP) in place to block external code insertions, it could prevent Whatfix from functioning on your app.

To prevent such issues and to resolve CSP violation errors, add the following domains as exceptions (Whitelisted) in the application's CSP headers. For more information, see Content Security Policy Reference.

Domains to Whitelist:

Subdomains to whitelist for all users (excluding EU data center users)

CSP directives to Whitelist for non-EU data centers

Subdomains to whitelist for EU data center users

CSP Directives to Whitelist for EU data centers

Subdomains to whitelist for all users (excluding EU data center users):

The following subdomains need to be whitelisted under all three CSP directives, that is, frame-src, connect-src, and script-src:

  • whatfix.com

  • cdn.whatfix.com

  • addons.whatfix.com

  • events.whatfix.com

  • videos.whatfix.com

Info:

Both https://whatfix.com and https://cdn.whatfix.com use Port 443, which is the port for the HTTPS Protocol.

Info:

The following domains also need to be whitelisted if Google Analytics is configured for your account:

CSP directives to whitelist for non-EU data centers:

Info:

  • Depending on the deployment model, whitelist only the necessary directives.

  • Whitelist Google Analytics (GA) domains only if you have GA configured for your account.

Deployment Model

CSP Directives

Domain/value

Export (Content on the same server)

connect-src

*whatfix.com

www.google-analytics.com

analytics.google.com

style-src

unsafe-inline

img-src

data:

www.google-analytics.com

analytics.google.com


Export (Content fetched from a different domain server)

connect-src

*whatfix.com

www.google-analytics.com

analytics.google.com

script-src

*.<domain>, <domain>

frame-src

style-src

unsafe-inline

img-src

data:

  www.google-analytics.com

analytics.google.com


CDN

connect-src

*.whatfix.com

*.whatfix.com

  www.google-analytics.com

analytics.google.com

script-src


*.whatfix.com

frame-src

style-src

unsafe-inline

img-src

www.google-analytics.com

analytics.google.com

data:


Extension

connect-src

  www.google-analytics.com

  analytics.google.com

img-src

data:

www.google-analytics.com

analytics.google.com


Dev script

connect-src

*.whatfix.com

*whatfix.com

www.google-analytics.com

analytics.google.com

img-src

data:

www.google-analytics.com

analytics.google.com

script-src

*.whatfix.com
*whatfix.com

frame-src

Note:

The following domain needs to be whitelisted for Survey responses to be captured.


https://survey-api-eus.whatfix.com 

Subdomains to whitelist for EU data center users:

The following subdomains need to be whitelisted under all three CSP directives, that is, frame-src, connect-src, and script-src:

  • eu.whatfix.com

  • eucdn.whatfix.com

  • euaddons.whatfix.com

  • videos.whatfix.com

CSP directives to whitelist for EU Data Centers

Deployment Model

CSP Directives

Domain/value

CDN

connect-src

*.whatfix.com

*.whatfix.com

script-src

*.whatfix.com

frame-src



Dev script

connect-src

*.whatfix.com
*whatfix.com

script-src

frame-src

Note:

The following domain needs to be whitelisted for the Survey responses to be captured:

https://survey-api-eu.whatfix.com 

Note:

  • Your IT Admin can help whitelist the domains mentioned.

  • If you are using any video or image links in your Whatfix content, whitelist those domains as well. For example, if you embed a YouTube video in a Pop-up, you need to whitelist youtube.com.

When do domains need whitelisting?

Whatfix recommends whitelisting the domains as soon as you start creating content on Whatfix. This way, content creators will not have any issues previewing and testing the content.

IP addresses to Whitelist

To ensure that Whatfix can access your organization's resources for crawling knowledge base content and integrations, you need to whitelist the certain IP addresses. For a list of all the IP addresses you need to whitelist, see IP Ranges.

Note:

IP addresses are the same for all users.


Best Practice

Ensure that you have applied the policy to every page, including error pages.

Privacy Policy | Whatfix Glossary | Whatfix Platform Status
Copyright © 2024 WHATFIX TM. All rights reserved.