Docs
Parcourir la documentation

Content Security Policy for the tracker

The Content Security Policy directives the analytics tracker needs (script-src, connect-src and img-src), plus the setup for nonces.

Voir en Markdown

If your site sends a Content-Security-Policy header, allow the tracker's script and its requests:

http
Content-Security-Policy: script-src 'self' https://privatusanalytics.com; connect-src 'self' https://privatusanalytics.com
Directive Why
script-src https://privatusanalytics.com Loads pa.js and any modules (pa.auto.js, pa.vitals.js, pa.clicks.js)
connect-src https://privatusanalytics.com Sends hits with fetch/sendBeacon to /api/event
img-src https://privatusanalytics.com Only for the no-JavaScript pixel

Add these to your existing directives and keep everything else you already allow.

The queue stub and nonces#

The queue stub is an inline script. With a strict CSP, give it your page's nonce (<script nonce="…">) or move it into a file you serve.

Symptoms of a CSP block#

In the console: Refused to load the script… (missing script-src) or Refused to connect to… (missing connect-src). The Verify installation check on Site settings → Tracking reads your CSP header and tells you which directive is missing. See CSP errors.