Skip to main content
PUT
Update security headers

Authorizations

Authorization
string
header
required

Personal access token, sent as Authorization: Bearer <token>.

Path Parameters

app_id
string
required

ID of the app.

Body

application/json
prevent_iframe_embedding
boolean

Set true to stop every site from showing the published app in a frame. Set false to lift that block, so framing follows the app's other settings and its workspace's policy again.

Example:

true

restrict_browser_features
boolean

Set true to make the published app send a restrictive Permissions-Policy header, or false to stop sending it.

Example:

true

Response

The app's security header settings after the change.

The app's security header settings.

result
SecurityHeadersSettingsResult · object
required

The app's security header settings.