Checkout Elements

Authorized Domains

Allow your own website to display embedded and overlay checkout.

Embedded and overlay checkout render the Fungies checkout inside a frame on your own website. The checkout only loads on the domains you have authorized for your workspace — on any other domain the frame stays blank.

Add every domain you plan to sell from before you ship the integration.

When you need it

IntegrationNeeds an authorized domain
SDK embed (mode: "embed")Yes — the domain hosting the page
SDK overlay (mode: "overlay")Yes — the domain hosting the page
HTML data attributesYes — the domain hosting the page
Hosted checkout linksNo
Your Fungies store domain (and your custom domain)No — always allowed

Local development counts too: http://localhost:3000 is a different origin from your production site and needs its own entry.

Add a domain

Open store settings

Go to Fungies Dashboard → Settings → Store → the Checkout tab.

Add the origin

In the Authorized domains card, click Add new domain and enter the full origin, e.g. https://example.com.

Save and reload

Click Save, then reload the page on your site that opens the checkout.

Your website must either link to or include your terms of service, privacy notice, and refund policy.

Accepted values

An entry is a full origin — scheme and host, nothing else.

ValueAcceptedNotes
https://example.comYes
https://www.example.comYesA separate entry from the apex domain
https://shop.example.comYesEvery subdomain needs its own entry
http://localhostYesLocal development
http://localhost:3000YesPort must match the one you serve on
example.comNoScheme is required
https://example.com/NoNo trailing slash
https://example.com/shopNoNo path
https://example.com:8443NoPorts are only accepted on localhost
http://example.comNoPlain http is only accepted on localhost
http://127.0.0.1:3000NoUse http://localhost:3000 instead

Origins are matched exactly. https://example.com does not cover https://www.example.com or any other subdomain — add each one you actually serve the checkout from.

What a missing domain looks like

The checkout frame opens and stays blank, and the browser console shows that the frame was refused — typically a message about the page refusing to connect or being blocked by frame-ancestors, depending on the browser.

If the checkout works when you open the checkout URL directly in a tab but not when embedded, a missing authorized domain is the first thing to check.

Troubleshooting

CheckDetail
Exact originThe entry must match the address bar's scheme and host exactly
Apex vs wwwServing both? Add both https://example.com and https://www.example.com
Subdomainshttps://shop.example.com needs its own entry
Localhost porthttp://localhost:3000 and http://localhost:5173 are different entries
ReloadReload the embedding page after saving — an already-loaded page keeps the old result
Staging sitesPreview and staging hosts are separate origins and need their own entries

Next Steps

Last updated