1. Help Center
  2. Frequently Asked Questions

Can Fundraise Up be used on a site with a CSP?

Fundraise Up can be used alongside a Content Security Policy (CSP).

If you’ve deployed a CSP, these are the full set of directives that Fundraise Up elements, checkout and tracking require:

connect-src
  fndrsp.net
  fndrsp-checkout.net
  *.fundraiseup.com
  *.stripe.com
*.paypal.com // optional, for PayPal payments
*.plaid.com // optional, for US bank transfers or stock donations
*.mastercard.com // optional, for Click To Pay
*.checkout.visa.com // optional, for Click To Pay
  api.addressy.com // optional, for UK based accounts

script-src
  *.fundraiseup.com
  *.stripe.com
  m.stripe.network
*.plaid.com // optional, for US bank transfers or stock donations
*.src.mastercard.com // optional, for Click To Pay
*.checkout.visa.com // optional, for Click To Pay
pay.google.com // optional, for Google Pay
*.paypal.com // optional, for PayPal payments

frame-src
   *.fundraiseup.com
   *.stripe.com
 *.plaid.com // optional, for US bank transfers or stock donations
 *.paypal.com // optional, for PayPal payments
 pay.google.com // optional, for Google Pay

img-src
   data:
   *.fundraiseup.com
   ucarecdn.com
 pay.google.com // optional, for Google Pay

font-src
   *.fundraiseup.com
   *.stripe.com

style-src
  'unsafe-inline'