---
updatedAt: 2025-11-17T12:38:17.000Z
agentTools:
  projectIndex: https://developers.tidio.com/llms.txt
---

# Content Security Policy

# Content Security Policy

If you are using Content Security Policy (CSP) on your site, you will need to add these entries to the policy to make widget work properly:

```
connect-src sentry-new.tidio.co socket.tidio.co wss://socket.tidio.co uploads.tidio.com;
img-src cdnjs.cloudflare.com unpkg.com data: code.tidio.co avatars.tidiochat.com tidio-images-messenger.s3.us-east-1.amazonaws.com;
media-src code.tidio.co;
script-src code.tidio.co;
style-src 'unsafe-inline';
font-src code.tidio.co data:;
```

> 📘 Info
>
> Please keep in mind that if you need to add inline scripts (e.g. for [visitor identification](/reference/visitor_identification)), consider using [nonce](https://content-security-policy.com/nonce/) or [hash](https://content-security-policy.com/hash/) instead of `'unsafe-inline'`.