Content Security Policy for the tracker
The Content Security Policy directives the analytics tracker needs (script-src, connect-src and img-src), plus the setup for nonces.
If your site sends a Content-Security-Policy header, allow the tracker's
script and its requests:
http
Content-Security-Policy: script-src 'self' https://privatusanalytics.com; connect-src 'self' https://privatusanalytics.com
| Directive | Why |
|---|---|
script-src https://privatusanalytics.com |
Loads pa.js and any modules (pa.auto.js, pa.vitals.js, pa.clicks.js) |
connect-src https://privatusanalytics.com |
Sends hits with fetch/sendBeacon to /api/event |
img-src https://privatusanalytics.com |
Only for the no-JavaScript pixel |
Add these to your existing directives and keep everything else you already allow.
The queue stub and nonces#
The queue stub is an inline
script. With a strict CSP, give it your page's nonce
(<script nonce="…">) or move it into a file you serve.
Symptoms of a CSP block#
In the console: Refused to load the script… (missing script-src) or
Refused to connect to… (missing connect-src). The Verify
installation check on Site settings → Tracking reads your CSP header and
tells you which directive is missing. See
CSP errors.