# Fix CSP errors blocking analytics

> Fix Content Security Policy errors that block the analytics tracker: add the host to script-src and connect-src, handle nonces, and find where your CSP is set.

Console errors like these mean your Content Security Policy blocks the
tracker:

- *Refused to load the script 'https://privatusanalytics.com/js/pa.js' because it
  violates the following Content Security Policy directive: "script-src …"*
- *Refused to connect to 'https://privatusanalytics.com/api/event' because it
  violates … "connect-src …"*

Add the host to both directives:

```http
Content-Security-Policy: script-src 'self' https://privatusanalytics.com; connect-src 'self' https://privatusanalytics.com
```

If you use the [queue stub](/docs/tracker/javascript-api#queue-stub) or
other inline scripts, give them your nonce.

Where's your CSP set? Check the response headers of your HTML page
(Network tab → the document → Response headers), and `<meta
http-equiv="Content-Security-Policy">` tags in the page. Frameworks and
hosts often set it in config: `next.config.js` headers, Helmet in Express,
`_headers` on Netlify, `vercel.json`, or a security plugin.

**Verify installation** (Site settings → Tracking) reads your CSP header
and tells you which directive is missing. Full reference:
[Content Security Policy](/docs/tracker/csp).
