curl --request GET \
--url https://app.base44.com/api/apps/{app_id}/security/headers \
--header 'Authorization: Bearer <token>'import requests
url = "https://app.base44.com/api/apps/{app_id}/security/headers"
headers = {"Authorization": "Bearer <token>"}
response = requests.get(url, headers=headers)
print(response.text)const options = {method: 'GET', headers: {Authorization: 'Bearer <token>'}};
fetch('https://app.base44.com/api/apps/{app_id}/security/headers', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://app.base44.com/api/apps/{app_id}/security/headers",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "https://app.base44.com/api/apps/{app_id}/security/headers"
req, _ := http.NewRequest("GET", url, nil)
req.Header.Add("Authorization", "Bearer <token>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.get("https://app.base44.com/api/apps/{app_id}/security/headers")
.header("Authorization", "Bearer <token>")
.asString();require 'uri'
require 'net/http'
url = URI("https://app.base44.com/api/apps/{app_id}/security/headers")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Get.new(url)
request["Authorization"] = 'Bearer <token>'
response = http.request(request)
puts response.read_body{
"result": {
"prevent_iframe_embedding": false,
"restrict_browser_features": false,
"embedding_origins": [
"https://partners.acme.com"
],
"org_embedding_origins": [
"https://partners.acme.com"
],
"org_prevent_iframe_embedding": false,
"app_policy": {
"mode": "allowlist",
"origins": [
"https://partners.acme.com"
]
},
"effective_policy": {
"mode": "allowlist",
"source": "app",
"origins": [
"https://partners.acme.com"
]
},
"app_allowlist_locked_by_workspace": false
}
}Get security headers
Returns the app’s security header settings, and the framing policy the published app follows once its workspace’s policy is applied.
Change prevent_iframe_embedding and restrict_browser_features with Update security headers. effective_policy is what the published app actually enforces, so read it rather than working the policy out from the other fields. When app_allowlist_locked_by_workspace is true, the workspace’s policy decides who can frame the app.
This is limited to 60 requests per minute per app for each workspace’s personal API keys, so every key in a workspace shares one allowance. Some workspaces have a different limit.
curl --request GET \
--url https://app.base44.com/api/apps/{app_id}/security/headers \
--header 'Authorization: Bearer <token>'import requests
url = "https://app.base44.com/api/apps/{app_id}/security/headers"
headers = {"Authorization": "Bearer <token>"}
response = requests.get(url, headers=headers)
print(response.text)const options = {method: 'GET', headers: {Authorization: 'Bearer <token>'}};
fetch('https://app.base44.com/api/apps/{app_id}/security/headers', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://app.base44.com/api/apps/{app_id}/security/headers",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "https://app.base44.com/api/apps/{app_id}/security/headers"
req, _ := http.NewRequest("GET", url, nil)
req.Header.Add("Authorization", "Bearer <token>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.get("https://app.base44.com/api/apps/{app_id}/security/headers")
.header("Authorization", "Bearer <token>")
.asString();require 'uri'
require 'net/http'
url = URI("https://app.base44.com/api/apps/{app_id}/security/headers")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Get.new(url)
request["Authorization"] = 'Bearer <token>'
response = http.request(request)
puts response.read_body{
"result": {
"prevent_iframe_embedding": false,
"restrict_browser_features": false,
"embedding_origins": [
"https://partners.acme.com"
],
"org_embedding_origins": [
"https://partners.acme.com"
],
"org_prevent_iframe_embedding": false,
"app_policy": {
"mode": "allowlist",
"origins": [
"https://partners.acme.com"
]
},
"effective_policy": {
"mode": "allowlist",
"source": "app",
"origins": [
"https://partners.acme.com"
]
},
"app_allowlist_locked_by_workspace": false
}
}Authorizations
Personal access token, sent as Authorization: Bearer <token>.
Path Parameters
ID of the app.
Response
The app's security header settings.
The app's security header settings.
The app's security header settings.
Show child attributes
Show child attributes
Was this page helpful?