Build a recommended Connection-Allowlist
Builds a Connection-Allowlist for the website from the Connection-Allowlist reports browsers sent over the period, and returns the header value in policy.
Without a policy, it starts from (response-origin), the origin each page is served from. With one, it keeps that allowlist. It then adds each destination browsers reported blocked as its origin, which allows every path on it, and collapses three or more subdomains of one site into a single *. pattern. A reported WebRTC connection turns on webrtc=allow. Browser extensions, anything that is not a plain origin, and noise (a destination reported fewer than 10 times in the period) are left out.
The allowlist ends with report-to=centralcsp. Send reportingEndpoints as the Reporting-Endpoints header alongside it. Connection-Allowlist is new and only Chromium-based browsers support it, so deploy it as Connection-Allowlist-Report-Only first and keep CSP connect-src alongside it.
The period defaults to the last 7 days and covers up to 30.
Anyone who knows the reporting endpoint can send reports to it, so a destination in the result is not proof that your pages connect to it. Review the added destinations before deploying: allowing a destination lets a script send data there.
Limited to 10 requests a minute for each person, after which it answers 429 with a Retry-After header.
Requires the viewer role on the website and the report:connection-allowlist plan feature.
An OpenID Connect access token from signing in to CentralCSP, acting as the signed-in user.
In: header
Path Parameters
The workspace's id.
The website's id.
Request Body
application/json
TypeScript Definitions
Use the request body type in TypeScript.
The period of reports to learn from and, optionally, the allowlist to start from.
How far back to read reports, counted from now. Defaults to 7d and is ignored when from and to are given.
Value in
- "24h"
- "7d"
- "14d"
- "30d"
Start of a calendar period instead of range. It must fall within the last 30 days and comes with to.
date-timeEnd of the calendar period, exclusive. It comes with from.
date-timeThe allowlist to start from, as a Connection-Allowlist header value without the header name. Leave it out to start from (response-origin).
1 <= length <= 16384Response Body
application/json
curl -X POST "https://example.com/v1/workspaces/01936b7a-6f2e-7c31-9a4d-2f8e1c5b7d90/websites/01936b7a-6f2e-7c31-9a4d-2f8e1c5b7d90/connection-allowlist/recommended-policy" \ -H "Content-Type: application/json" \ -d '{}'{ "policy": "(response-origin \"https://api.example.com\" \"https://*.cdn.example.com\"); report-to=centralcsp", "reportingEndpoints": "centralcsp=\"https://e0123456789abcdef0123.report.centralcsp.com\", default=\"https://e0123456789abcdef0123.report.centralcsp.com\""}Build a recommended Permissions-Policy POST
Builds a Permissions-Policy for the website from the Permissions-Policy reports browsers sent over the period, and returns the header value in policy.
Export individual reports GET
Streams individual reports as CSV, newest first, with the same filters as the list endpoint and no pagination. The columns depend on the report type.