Skip to main content
Guides

Domain Protection

Restrict which domains can load your deployed scripts.

Domain protection limits script execution to approved domains. Scripts loaded from unapproved domains are blocked.

Enable Domain Protection

  1. Open the Domains icon in the left activity bar.
  2. Turn on Domain protection.
  3. Add domains individually. Wildcard patterns are supported (e.g., *.example.com).
  4. localhost is always allowed regardless of the domain list.

Any host configured under Staging Domains is also allowed, whether or not it appears in this list.

Propagation

Changes take approximately 60 seconds to apply. Domain rules are stored in Cloudflare KV and checked at the edge.

Plan Requirement

Domain protection requires the Beta, Individual, or Team plan. Free plan users see an upgrade prompt. See Plans and Limits.

Troubleshooting

If your script is blocked unexpectedly, verify:

  1. The domain is in the allowed list (check for typos).
  2. Wildcard patterns match the full domain.
  3. Wait 60 seconds after adding a domain for propagation.

See Domain Protection Blocking.