Fix CSP errors blocking analytics
Fix Content Security Policy errors that block the analytics tracker: add the host to script-src and connect-src, handle nonces, and find where your CSP is set.
Console errors like these mean your Content Security Policy blocks the tracker:
- Refused to load the script 'https://privatusanalytics.com/js/pa.js' because it violates the following Content Security Policy directive: "script-src …"
- Refused to connect to 'https://privatusanalytics.com/api/event' because it violates … "connect-src …"
Add the host to both directives:
Content-Security-Policy: script-src 'self' https://privatusanalytics.com; connect-src 'self' https://privatusanalytics.com
If you use the queue stub or other inline scripts, give them your nonce.
Where's your CSP set? Check the response headers of your HTML page
(Network tab → the document → Response headers), and <meta
http-equiv="Content-Security-Policy"> tags in the page. Frameworks and
hosts often set it in config: next.config.js headers, Helmet in Express,
_headers on Netlify, vercel.json, or a security plugin.
Verify installation (Site settings → Tracking) reads your CSP header and tells you which directive is missing. Full reference: Content Security Policy.