---
title: Content Security Policy (CSP)
slug: content-security-policy-csp
icon: 🔐
docTags: 
createdAt: 2025-07-26T11:47:53.417Z
---

:::hint{type="info"}
**Who is this for:** Developers implementing MomentScience products on websites or apps that enforce a strict Content Security Policy.

**Outcome:** Identify and add all required MomentScience domains to the correct CSP directives so assets, APIs, fonts, and tracking scripts load without being blocked.
:::

# Overview

When implementing MomentScience products, including Perkswall, Moments, and other native Offer experiences, you may need to define a strict Content Security Policy (CSP) to meet your security or compliance requirements.

This guide outlines the domains that should be explicitly allowed in your CSP configuration to ensure all assets load correctly. These domains support key features such as API communication, creative rendering, analytics tracking, embedded content, and styling.

If your site blocks external scripts, fonts, or other resources by default, be sure to add the domains listed below to the appropriate directives.

# Required Domains by CSP Directive

### `connect-src`

Used for backend API calls, event tracking, and offer delivery services:

:::CodeblockTabs
connect-src

```bash
https://api.adspostx.com  
https://trk.adspostx.com  
https://trk.pubtailer.com  
https://trk-e.pubtailer.com  
https://e.pubtailer.com  
https://api.perskwallet.com  
```
:::

***

### `font-src`

Required for loading fonts used in MomentScience user experiences:

:::CodeblockTabs
font-src

```text
https://cdn.pubtailer.com  
https://adpx.b-cdn.net  
https://fonts.gstatic.com  
https://fonts.googleapis.com  
```
:::

***

### `frame-src`

Used for embedding components such as Perkswall and Moments:

:::CodeblockTabs
frame-src

```text
https://cdn.pubtailer.com  
https://get.perkswall.com  
```
:::

***

### `img-src`

Domains used to serve offer creatives, icons, and tracking pixels:

:::CodeblockTabs
img-src

```text
https://api.adspostx.com  
https://cdn.pubtailer.com  
https://trk.pubtailer.com  
https://trk-e.pubtailer.com  
https://e.pubtailer.com  
https://adpx.b-cdn.net  
```
:::

***

### `script-src-elem`

Sources for JavaScript libraries, SDKs, and analytics scripts:

:::CodeblockTabs
script-src-elem

```text
https://cdn.pubtailer.com  
https://naojs.pubtailer.com  
https://trk.pubtailer.com  
https://trk-e.pubtailer.com  
https://e.pubtailer.com  
```
:::

***

### `script-src-attr`

Required if inline event handlers or dynamically generated scripts are restricted:

:::CodeblockTabs
script-src-attr

```text
https://cdn.pubtailer.com  
https://naojs.pubtailer.com  
https://trk.pubtailer.com  
https://trk-e.pubtailer.com  
https://e.pubtailer.com  
```
:::

***

### `style-src-elem`

Used for loading stylesheets required by Moments and Perkswall experiences:

:::CodeblockTabs
style-src-elem

```text
https://cdn.pubtailer.com  
https://naojs.pubtailer.com  
https://trk.pubtailer.com  
https://trk-e.pubtailer.com  
https://e.pubtailer.com  
https://api.adspostx.com  
```
:::

***

### `style-src-attr`

Include these sources if you restrict inline style attributes:

:::CodeblockTabs
style-src-attr

```text
https://cdn.pubtailer.com  
https://naojs.pubtailer.com  
https://trk.pubtailer.com  
https://trk-e.pubtailer.com  
https://e.pubtailer.com  
https://api.adspostx.com  
```
:::

***

📢 If you're running into any issues while going through the integration process, feel free to contact us at [help@momentscience.com](mailto\:help@Momentscience.com)
