# Content Security Policy for the tracker

> The Content Security Policy directives the analytics tracker needs (script-src, connect-src and img-src), plus the setup for nonces.

If your site sends a `Content-Security-Policy` header, allow the tracker's
script and its requests:

```http
Content-Security-Policy: script-src 'self' https://privatusanalytics.com; connect-src 'self' https://privatusanalytics.com
```

| Directive | Why |
|---|---|
| `script-src https://privatusanalytics.com` | Loads `pa.js` and any [modules](/docs/tracker/modules) (`pa.auto.js`, `pa.vitals.js`, `pa.clicks.js`) |
| `connect-src https://privatusanalytics.com` | Sends hits with `fetch`/`sendBeacon` to `/api/event` |
| `img-src https://privatusanalytics.com` | Only for the [no-JavaScript pixel](/docs/install/pixel) |

Add these to your existing directives and keep everything else you already
allow.

## The queue stub and nonces

The [queue stub](/docs/tracker/javascript-api#queue-stub) is an inline
script. With a strict CSP, give it your page's nonce
(`<script nonce="…">`) or move it into a file you serve.

## Symptoms of a CSP block

In the console: *Refused to load the script…* (missing `script-src`) or
*Refused to connect to…* (missing `connect-src`). The **Verify
installation** check on Site settings → Tracking reads your CSP header and
tells you which directive is missing. See
[CSP errors](/docs/troubleshooting/csp).
