Skip to content

Site Compatibility Check ​

Some websites send security headers that control which outside services a page may load. The most common one is a Content-Security-Policy. If those headers don't include Videobot, the widget or its videos won't appear.

Enter the address of a page where Videobot is (or will be) shown. We'll check the page's headers and tell you exactly what, if anything, needs to change.

Use a page where Videobot is (or will be) shown. Some sites send different headers on different pages.

Videobot is moving to its own streaming domains

Videos are moving from Cloudflare Stream to Videobot's own streaming service on *.videobot.com addresses. If your site's policy only lists Cloudflare, videos will stop playing once your account moves. Adding https://videobot.com and https://*.videobot.com covers Videobot now and in the future.

Who does what ​

  • Videobot support or your marketing team: run the check and use Copy link to this check or Copy report.
  • Your web developer: add the values under For your web developer to the site's Content-Security-Policy. They usually live in the web server, CDN or CMS security settings. Then run the check again.

Complete allowlist ​

These are all the values Videobot needs in a Content-Security-Policy. Add them to your existing directives. If a directive isn't in your policy, add the values to default-src instead.

DirectiveAdd
script-srchttps://videobot.com
frame-srchttps://videobot.com
connect-srchttps://*.videobot.comhttps://*.cloudflarestream.com (recommended)
media-srchttps://*.videobot.comblob:https://*.cloudflarestream.com (recommended)
img-srchttps://*.videobot.comhttps://*.cloudflarestream.com (recommended)https://imagedelivery.net (recommended)
style-src'unsafe-inline'
worker-srcblob: (recommended)

*.videobot.com does not include videobot.com

A wildcard only matches subdomains. The Videobot script and player load from https://videobot.com, so list it separately.

"Recommended" values are needed for videos that haven't moved to Videobot's own streaming yet, and for future player updates. Without them, Videobot still loads, but some older videos may not play.

Other headers ​

  • Permissions-Policy: if your site sends one, it must let https://videobot.com use autoplay, fullscreen, clipboard-write and web-share, for example autoplay=(self "https://videobot.com"). If the header doesn't mention a feature, nothing needs to change.
  • Cross-Origin-Embedder-Policy: require-corp or credentialless stops the Videobot player from loading. Remove it on pages that show Videobot.
  • External links: if a Videobot opens an external web page inside the player, that page's address must also be in frame-src.