What the SDK connects to
- Frames load from the card-data processor’s embed origin, listed below. This is the only cross-origin network activity the SDK introduces.
- No extra
connect-srcis needed for the SDK itself. Your ownfetchSessioncall to your backend uses whatever origin your backend lives on. Allow that origin under your existing policy, as you would any first-party API call. - No extra
img-srcorfont-srcis needed. The default card face self-hosts its fonts from your own origin — they ship inside the package — and the SDK loads no remote images.
frame-src origins per environment
Allow the origin that matches the environment you construct DakotaCards with:
A policy for a production page that reveals cards looks like this:
https://sandbox.lithic.com instead. If your app uses both environments, list both origins in frame-src.
Frames from these origins carry the session token in their URL. If your page runs monitoring, session replay, or error tracking, keep the token out of it.
Protecting your own reveal page (frame-ancestors)
The origins above control what your page may embed. To stop a third party from embedding your reveal page and tricking a cardholder into revealing details inside a hostile frame (clickjacking), set frame-ancestors on the responses that serve your reveal UI:
'none' if your reveal page is never meant to be framed, or list the specific parent origins that legitimately embed it. This directive controls who may frame you. It is independent of the frame-src allowlist above.

