Allowed origins

Restrict which websites can submit to a form. Allowed origins stop other sites from using your endpoint and set CORS headers.

1 minUpdated

By default, any website can submit to a form's endpoint. Allowed origins restrict each form to your own domains.

How do I set allowed origins?

Open Form → Settings → Allowed origins and add one origin per line:

https://example.com
https://www.example.com

An origin is the scheme and host, plus the port if it isn't the default: https://example.com, http://localhost:4321. Paths are ignored, so https://example.com/contact is saved as https://example.com. Each form has its own list, so a form embedded on two sites can allow both.

What happens to other origins?

Submissions from any other origin are rejected with 403 This site is not allowed to submit to this form. SiteBackend reads the browser's Origin header, or the Referer when there's no Origin.

Does this affect CORS?

Yes. For fetch requests, SiteBackend returns your origin in Access-Control-Allow-Origin when it's allowed. With no allowed origins set on the form, it returns *.

Do allowed origins apply to testimonials?

No. Allowed origins are set per form. Testimonial collect forms and widgets use the site's domain instead: set it in Site → Settings and they only load on that domain, its subdomains and localhost. See sites.