Content-Security-Policy
If your site sends a Content-Security-Policy (aContent-Security-Policy header or <meta http-equiv> tag), the browser refuses every script, request, frame or image from an origin the policy does not list. A Headless SDK checkout needs two sets of origins:
- The checkout itself — TagadaPay, Basis Theory (card tokenization) and Stripe (express checkout). Always the same.
- The pixels of your coded funnel — Meta, TikTok, Snapchat, Google Tag Manager, Microsoft Clarity: only those you bound on the canvas are needed. They are listed per provider below.
npx tagada funnel csp prints both.
A site without a CSP has nothing to do.
From the command line
The command needs no API key. It requires
@tagadapay/node-sdk 3.26.0 or later; earlier versions print the checkout origins only.
From code
@tagadapay/node-sdk (and @tagadapay/node-sdk/edge, for edge runtimes) exports the checkout origins as CSP_ORIGINS, and withTagadaCsp(policy) merges them into your own directives without duplicates. They do not include the pixels: add the rows of the table below yourself.
If you load the SDK with the CDN script tag, also allow
https://cdn.jsdelivr.net in script-src: the SDK and its pixel file, tagada-pixels.min.js, are served from there.Pixels
Add the rows of every provider you bound on the canvas:
Google Tag Manager loads whatever tags your container holds: if one of them calls another vendor, that vendor’s origins are needed too.
When something is still blocked
A pixel the CSP blocks is reported by the SDK and shows up in SDK health as Pixel blocked by your CSP, with the provider and the domain it failed on. On the page itself, the browser console names the refused URL and the directive that refused it, andawait tagada.track.health() lists the blocked pixels.