Skip to content

Security and privacy

Content Security Policy

The directives your CSP needs for the PlayStep web SDK.

The SDK uses no eval and no inline scripts, and draws its UI in a shadow root with its own stylesheet. If your site sends a Content-Security-Policy, allow:

script-src  https://cdn.playstep.app
connect-src https://cdn.playstep.app https://api.playstep.app
media-src   https://clips.playstep.app
img-src     https://clips.playstep.app https://i.ytimg.com
style-src   'unsafe-inline'
  • style-src 'unsafe-inline' is for the stylesheet inside the shadow root. If your policy cannot allow it, contact us for a nonce-based build.
  • Add your own hosts to media-src and img-src if you use external clips.
  • For YouTube and Vimeo embeds, add frame-src https://www.youtube-nocookie.com https://player.vimeo.com.
  • With @playstep/web from npm, script-src needs only your own origin.

Search the docs and guides.

PlayStep is coming soon

We're opening PlayStep to teams one at a time. Leave your name and email and we'll set up a demo.

We use your email only to arrange the demo. See the privacy policy.