curl --request PUT \
--url https://app.base44.com/api/apps/{app_id}/security/headers \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"prevent_iframe_embedding": true
}
'import requests
url = "https://app.base44.com/api/apps/{app_id}/security/headers"
payload = { "prevent_iframe_embedding": True }
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.put(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'PUT',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({prevent_iframe_embedding: true})
};
fetch('https://app.base44.com/api/apps/{app_id}/security/headers', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://app.base44.com/api/apps/{app_id}/security/headers",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "PUT",
CURLOPT_POSTFIELDS => json_encode([
'prevent_iframe_embedding' => true
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://app.base44.com/api/apps/{app_id}/security/headers"
payload := strings.NewReader("{\n \"prevent_iframe_embedding\": true\n}")
req, _ := http.NewRequest("PUT", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.put("https://app.base44.com/api/apps/{app_id}/security/headers")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"prevent_iframe_embedding\": true\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://app.base44.com/api/apps/{app_id}/security/headers")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Put.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"prevent_iframe_embedding\": true\n}"
response = http.request(request)
puts response.read_body{
"result": {
"prevent_iframe_embedding": false,
"restrict_browser_features": false,
"embedding_origins": [
"https://partners.acme.com"
],
"org_embedding_origins": [
"https://partners.acme.com"
],
"org_prevent_iframe_embedding": false,
"app_policy": {
"mode": "allowlist",
"origins": [
"https://partners.acme.com"
]
},
"effective_policy": {
"mode": "allowlist",
"source": "app",
"origins": [
"https://partners.acme.com"
]
},
"app_allowlist_locked_by_workspace": false
}
}Update security headers
Changes the app’s security header settings and returns them as they now stand.
Send only the settings you want to change. A setting you leave out keeps its value.
A change applies to the published app right away, with no need to deploy it again. It doesn’t affect the builder’s preview.
Turning on a setting that Get security scan recommends in header_recommendations removes that recommendation from the scan result.
This is limited to 30 requests a minute per app for each workspace’s personal API keys, so every key in a workspace shares one allowance. Some workspaces have a different limit.
curl --request PUT \
--url https://app.base44.com/api/apps/{app_id}/security/headers \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"prevent_iframe_embedding": true
}
'import requests
url = "https://app.base44.com/api/apps/{app_id}/security/headers"
payload = { "prevent_iframe_embedding": True }
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.put(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'PUT',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({prevent_iframe_embedding: true})
};
fetch('https://app.base44.com/api/apps/{app_id}/security/headers', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://app.base44.com/api/apps/{app_id}/security/headers",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "PUT",
CURLOPT_POSTFIELDS => json_encode([
'prevent_iframe_embedding' => true
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://app.base44.com/api/apps/{app_id}/security/headers"
payload := strings.NewReader("{\n \"prevent_iframe_embedding\": true\n}")
req, _ := http.NewRequest("PUT", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.put("https://app.base44.com/api/apps/{app_id}/security/headers")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"prevent_iframe_embedding\": true\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://app.base44.com/api/apps/{app_id}/security/headers")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Put.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"prevent_iframe_embedding\": true\n}"
response = http.request(request)
puts response.read_body{
"result": {
"prevent_iframe_embedding": false,
"restrict_browser_features": false,
"embedding_origins": [
"https://partners.acme.com"
],
"org_embedding_origins": [
"https://partners.acme.com"
],
"org_prevent_iframe_embedding": false,
"app_policy": {
"mode": "allowlist",
"origins": [
"https://partners.acme.com"
]
},
"effective_policy": {
"mode": "allowlist",
"source": "app",
"origins": [
"https://partners.acme.com"
]
},
"app_allowlist_locked_by_workspace": false
}
}Authorizations
Personal access token, sent as Authorization: Bearer <token>.
Path Parameters
ID of the app.
Body
Set true to stop every site from showing the published app in a frame. Set false to lift that block, so framing follows the app's other settings and its workspace's policy again.
true
Set true to make the published app send a restrictive Permissions-Policy header, or false to stop sending it.
true
Response
The app's security header settings after the change.
The app's security header settings.
The app's security header settings.
Show child attributes
Show child attributes
Was this page helpful?