Authorized Domains
Allow your own website to display embedded and overlay checkout.
Embedded and overlay checkout render the Fungies checkout inside a frame on your own website. The checkout only loads on the domains you have authorized for your workspace — on any other domain the frame stays blank.
Add every domain you plan to sell from before you ship the integration.
When you need it
| Integration | Needs an authorized domain |
|---|---|
SDK embed (mode: "embed") | Yes — the domain hosting the page |
SDK overlay (mode: "overlay") | Yes — the domain hosting the page |
| HTML data attributes | Yes — the domain hosting the page |
| Hosted checkout links | No |
| Your Fungies store domain (and your custom domain) | No — always allowed |
Local development counts too: http://localhost:3000 is a different origin from your production
site and needs its own entry.
Add a domain
Open store settings
Go to Fungies Dashboard → Settings → Store → the Checkout tab.
Add the origin
In the Authorized domains card, click Add new domain and enter the full origin, e.g.
https://example.com.
Save and reload
Click Save, then reload the page on your site that opens the checkout.
Your website must either link to or include your terms of service, privacy notice, and refund policy.
Accepted values
An entry is a full origin — scheme and host, nothing else.
| Value | Accepted | Notes |
|---|---|---|
https://example.com | Yes | |
https://www.example.com | Yes | A separate entry from the apex domain |
https://shop.example.com | Yes | Every subdomain needs its own entry |
http://localhost | Yes | Local development |
http://localhost:3000 | Yes | Port must match the one you serve on |
example.com | No | Scheme is required |
https://example.com/ | No | No trailing slash |
https://example.com/shop | No | No path |
https://example.com:8443 | No | Ports are only accepted on localhost |
http://example.com | No | Plain http is only accepted on localhost |
http://127.0.0.1:3000 | No | Use http://localhost:3000 instead |
Origins are matched exactly. https://example.com does not cover https://www.example.com or
any other subdomain — add each one you actually serve the checkout from.
What a missing domain looks like
The checkout frame opens and stays blank, and the browser console shows that the frame was refused —
typically a message about the page refusing to connect or being blocked by frame-ancestors,
depending on the browser.
If the checkout works when you open the checkout URL directly in a tab but not when embedded, a missing authorized domain is the first thing to check.
Troubleshooting
| Check | Detail |
|---|---|
| Exact origin | The entry must match the address bar's scheme and host exactly |
Apex vs www | Serving both? Add both https://example.com and https://www.example.com |
| Subdomains | https://shop.example.com needs its own entry |
| Localhost port | http://localhost:3000 and http://localhost:5173 are different entries |
| Reload | Reload the embedding page after saving — an already-loaded page keeps the old result |
| Staging sites | Preview and staging hosts are separate origins and need their own entries |
Next Steps
Last updated