OptionalconnectDomains allowed for fetch/XHR/WebSocket connections. Maps to connect-src directive.
OptionalframeAllowed iframe origins. ChatGPT only - discouraged for security reasons.
OptionalredirectDomains for openExternal without confirmation modal. ChatGPT only - ignored on MCP Apps.
OptionalresourceDomains allowed for images, scripts, stylesheets, fonts. Maps to img-src, script-src, style-src, font-src directives.
Content Security Policy configuration
Unified CSP interface that maps to protocol-specific formats:
_meta.ui.csp.{connectDomains, resourceDomains}_meta["openai/widgetCSP"].{connect_domains, resource_domains, ...}