> ## Documentation Index
> Fetch the complete documentation index at: https://docs.base44.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Update security headers

> <Info>This API is in beta. Endpoints, fields, and behavior may still change, so avoid depending on it in production.</Info>

Changes the app's security header settings and returns them as they now stand.

Send only the settings you want to change. A setting you leave out keeps its value.

A change applies to the published app right away, with no need to deploy it again. It doesn't affect the builder's preview.

Turning on a setting that [Get security scan](/api-reference/get-security-scan) recommends in `header_recommendations` removes that recommendation from the scan result.

This is limited to 30 requests a minute per app for each workspace's personal API keys, so every key in a workspace shares one allowance. Some workspaces have a different limit.

<Note>This endpoint accepts a personal API key belonging to a user with editor access to the app. A read-only key is refused, and workspace API keys are not accepted.</Note>



## OpenAPI

````yaml /developers/references/app-management/app-management-openapi.json put /api/apps/{app_id}/security/headers
openapi: 3.1.0
info:
  title: Base44 App Management API
  version: 1.0.0
servers:
  - url: https://app.base44.com
security:
  - PersonalAccessTokenAuth: []
paths:
  /api/apps/{app_id}/security/headers:
    put:
      summary: Update security headers
      description: >-
        <Info>This API is in beta. Endpoints, fields, and behavior may still
        change, so avoid depending on it in production.</Info>


        Changes the app's security header settings and returns them as they now
        stand.


        Send only the settings you want to change. A setting you leave out keeps
        its value.


        A change applies to the published app right away, with no need to deploy
        it again. It doesn't affect the builder's preview.


        Turning on a setting that [Get security
        scan](/api-reference/get-security-scan) recommends in
        `header_recommendations` removes that recommendation from the scan
        result.


        This is limited to 30 requests a minute per app for each workspace's
        personal API keys, so every key in a workspace shares one allowance.
        Some workspaces have a different limit.


        <Note>This endpoint accepts a personal API key belonging to a user with
        editor access to the app. A read-only key is refused, and workspace API
        keys are not accepted.</Note>
      operationId: update_security_headers_settings_api_apps__app_id__security_headers_put
      parameters:
        - name: app_id
          in: path
          required: true
          schema:
            type: string
            description: ID of the app.
            title: App Id
          description: ID of the app.
          example: 6820f3a4e7b91d003c45a1f2
      requestBody:
        required: true
        content:
          application/json:
            schema:
              title: UpdateSecurityHeaders
              type: object
              properties:
                prevent_iframe_embedding:
                  type: boolean
                  description: >-
                    Set `true` to stop every site from showing the published app
                    in a frame. Set `false` to lift that block, so framing
                    follows the app's other settings and its workspace's policy
                    again.
                  example: true
                restrict_browser_features:
                  type: boolean
                  description: >-
                    Set `true` to make the published app send a restrictive
                    `Permissions-Policy` header, or `false` to stop sending it.
                  example: true
            example:
              prevent_iframe_embedding: true
      responses:
        '200':
          description: The app's security header settings after the change.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/SecurityHeadersSettingsResponse'
        '401':
          description: Missing or invalid credentials.
        '403':
          description: >-
            You don't have editor access to this app, your API key is read-only,
            or you used a workspace API key.
        '404':
          description: App not found.
        '422':
          description: >-
            The body is missing or isn't a JSON object, has an unknown field, or
            has a value that can't be read as a boolean.
        '429':
          description: Too many updates for this app in the last minute.
components:
  schemas:
    SecurityHeadersSettingsResponse:
      properties:
        result:
          $ref: '#/components/schemas/SecurityHeadersSettingsResult'
          description: The app's security header settings.
      type: object
      required:
        - result
      title: SecurityHeadersSettingsResponse
      description: The app's security header settings.
    SecurityHeadersSettingsResult:
      properties:
        prevent_iframe_embedding:
          type: boolean
          title: Prevent Iframe Embedding
          description: >-
            Whether the app blocks every site from showing it in a frame
            (`true`) or not (`false`). When `true`, the published app sends
            `X-Frame-Options: DENY`.
          example: false
        restrict_browser_features:
          type: boolean
          title: Restrict Browser Features
          description: >-
            Whether the published app sends a restrictive `Permissions-Policy`
            header (`true`) or not (`false`). It lets only the app's own pages
            use the camera, microphone, location, payment, and USB features, and
            turns off the magnetometer and gyroscope.
          example: false
        embedding_origins:
          anyOf:
            - items:
                type: string
              type: array
            - type: 'null'
          title: Embedding Origins
          description: >-
            Sites the app itself allows to frame it, or `null` when the app has
            no list of its own.
          example:
            - https://partners.acme.com
        org_embedding_origins:
          anyOf:
            - items:
                type: string
              type: array
            - type: 'null'
          title: Org Embedding Origins
          description: >-
            Sites the app's workspace allows to frame its apps, or `null` when
            the workspace sets no list or its plan doesn't include one.
          example:
            - https://partners.acme.com
        org_prevent_iframe_embedding:
          type: boolean
          title: Org Prevent Iframe Embedding
          description: >-
            Whether the app's workspace blocks framing for all of its apps
            (`true`) or not (`false`).
          example: false
        app_policy:
          $ref: '#/components/schemas/AppEmbeddingPolicyResult'
          description: The framing policy set on the app itself.
        effective_policy:
          $ref: '#/components/schemas/EffectiveEmbeddingPolicyResult'
          description: >-
            The framing policy the published app actually sends, after the
            workspace policy is applied.
        app_allowlist_locked_by_workspace:
          type: boolean
          title: App Allowlist Locked By Workspace
          description: >-
            Whether the app's workspace controls which sites can frame its apps
            (`true`), so the app can't set a list of its own, or not (`false`).
          example: false
      type: object
      required:
        - prevent_iframe_embedding
        - restrict_browser_features
        - embedding_origins
        - org_embedding_origins
        - org_prevent_iframe_embedding
        - app_policy
        - effective_policy
        - app_allowlist_locked_by_workspace
      title: SecurityHeadersSettingsResult
      description: Security header settings for one app.
    AppEmbeddingPolicyResult:
      properties:
        mode:
          type: string
          enum:
            - inherit
            - block_all
            - allowlist
          title: Mode
          description: >-
            What the app's own setting says. `inherit` means the app sets no
            policy and follows its workspace, `block_all` means no site can
            frame it, and `allowlist` means only `origins` can.
          example: allowlist
        origins:
          anyOf:
            - items:
                type: string
              type: array
            - type: 'null'
          title: Origins
          description: >-
            Sites allowed to frame the app when `mode` is `allowlist`, or `null`
            for the other modes.
          example:
            - https://partners.acme.com
      type: object
      required:
        - mode
        - origins
      title: AppEmbeddingPolicyResult
      description: An app's own framing policy.
    EffectiveEmbeddingPolicyResult:
      properties:
        mode:
          type: string
          enum:
            - anyone
            - block_all
            - allowlist
          title: Mode
          description: >-
            Who can show the published app in a frame. `anyone` means any site
            can, `block_all` means no site can, and `allowlist` means only
            `origins` can.
          example: allowlist
        source:
          type: string
          enum:
            - default
            - app
            - workspace
          title: Source
          description: >-
            Where the policy comes from. `app` is the app's own setting,
            `workspace` is its workspace's policy, and `default` means neither
            sets one.
          example: app
        origins:
          anyOf:
            - items:
                type: string
              type: array
            - type: 'null'
          title: Origins
          description: >-
            Sites allowed to frame the app when `mode` is `allowlist`, or `null`
            for the other modes.
          example:
            - https://partners.acme.com
      type: object
      required:
        - mode
        - source
        - origins
      title: EffectiveEmbeddingPolicyResult
      description: A published app's framing policy after its workspace policy is applied.
  securitySchemes:
    PersonalAccessTokenAuth:
      type: http
      scheme: bearer
      description: 'Personal access token, sent as `Authorization: Bearer <token>`.'

````