If your website uses a Content Security Policy (CSP), it must allow the resources and network requests required by the Dacast video player.
Dacast currently uses two web players: THEOplayer and Bitmovin. Their licensing and analytics services are different. Depending on the player, browser, device, and enabled features, additional requests may be needed for video delivery, public IP address lookup, casting, or other functionality.
An overly restrictive CSP can cause problems that are not immediately obvious:
- Video playback may fail. Viewers might see an offline message or be unable to play a video.
- Video may play while analytics are missing. CSP can block analytics requests without interrupting playback. As a result, reported views and other audience metrics may be incomplete.
- Other player features may not work correctly. For example, blocking a licensing request or a script required by an optional feature can affect that feature.
Important: Successfully playing a video does not confirm that viewer analytics are being collected.
1. Which domains should your CSP allow?
The following table lists domains observed during Dacast VOD playback tests with THEOplayer and Bitmovin, along with the relevant CSP directives. Not every domain is needed for every integration or feature.
| Purpose | Player | Domain to allow | CSP directive |
|---|---|---|---|
| Dacast iframe embed | Both | https://iframe.dacast.com | frame-src |
| Player scripts and other Dacast resources | Both | https://*.dacast.com | script-src, style-src, img-src, and other applicable directives |
| Video delivery | Both | https://*.dacast.com | media-src and connect-src |
| Player licensing | Bitmovin | https://licensing.bitmovin.com | connect-src |
| Viewer analytics | Bitmovin | https://analytics-ingress-global.bitmovin.com | connect-src |
| Player licensing | THEOplayer | https://license.theoplayer.com | connect-src |
| Viewer analytics | THEOplayer | https://kinesis.us-east-1.amazonaws.com | connect-src |
| Public IP address lookup | THEOplayer, when used | https://api.ipify.org | connect-src |
| Chromecast / Cast to TV functionality (when available) | Both | https://www.gstatic.com | script-src |
These are not necessarily the only domains your integration will use. Live streaming, DRM, paywalls, other delivery networks, and optional features may require additional sources. If a browser reports a CSP violation involving another domain, ask your website developer to review that request and add the appropriate source to the relevant directive.
Why are both media-src and connect-src listed for video?
Browsers and players do not always load video in the same way.
A browser using native video playback may load a media resource under media-src. A JavaScript-based player may retrieve playlists and video segments using fetch or XMLHttpRequest, which are governed by connect-src.
For this reason, permitting a Dacast domain in connect-src does not automatically permit it in media-src, or vice versa.
Why are analytics domains listed separately?
Bitmovin and THEOplayer send analytics to different services.
For Bitmovin, the player must be able to communicate with Bitmovin Analytics. For THEOplayer, Dacast viewer analytics use an AWS Kinesis endpoint.
If these requests are blocked by CSP, viewers may still be able to watch the video, but their activity may not be recorded in Dacast Analytics.
2. How to update the relevant CSP directives
Your website administrator should add the required sources to your existing CSP, keeping all other allowed sources and security directives intact.
For example, a website using Bitmovin might need the following entries:
- media-src ‘self’ https://*.dacast.com;
- connect-src ‘self’ https://*.dacast.com https://*.bitmovin.com;
A website using THEOplayer might need:
- media-src ‘self’ https://*.dacast.com;
- connect-src ‘self’ https://*.dacast.com https://license.theoplayer.com
- https://kinesis.us-east-1.amazonaws.com https://api.ipify.org;
These examples show only two CSP directives, not a complete policy. They must not be copied over your website’s entire CSP header.
The Bitmovin example uses https://*.bitmovin.com to cover both its licensing and analytics subdomains. Your administrator may instead allow the individual hostnames listed in the table if your security requirements call for a more restrictive policy.
If your website may use either Dacast player, ensure its policy accommodates the services required by both.
3. Where to find and update your CSP
CSP is a security setting configured by your website or its hosting infrastructure. It is not a setting that individual viewers need to change in their browser or firewall.
The exact location depends on how your website is built and hosted. Your website administrator or hosting provider should check the following common locations:
| Where CSP may be configured | What to look for |
|---|---|
| Website application | Security middleware or application settings that generate the Content-Security-Policy HTTP response header |
| CMS or security plugin | Website security settings, HTTP response headers, or a Content Security Policy configuration page |
| Nginx web server | An add_header Content-Security-Policy directive |
| Apache web server | A Header set Content-Security-Policy directive |
| IIS web server | HTTP Response Headers or a rule in web.config |
| CDN, WAF, or reverse proxy | Rules that add or modify HTTP response headers |
If you are unsure which system controls your CSP, ask the team managing your website to locate the configuration that generates the Content-Security-Policy response header.
How to inspect your current policy
Your website developer can check which policy the browser receives:
- Open the webpage containing the Dacast video in Chrome or Edge on a computer.
- Press F12 to open Developer Tools and select Network.
- Reload the page.
- Select the request for the webpage itself, usually marked Document.
- Open Response Headers and locate Content-Security-Policy.
This shows the policy delivered to the browser, although it may not reveal where the policy is configured. Your developer should also check whether the HTML contains a CSP <meta> tag.
If you embed Dacast using an iframe: the CSP of your website and the CSP of the document inside the iframe are separate. Your website’s frame-src must permit the Dacast iframe, but changing your website’s CSP may not resolve a request blocked inside the iframe. The browser’s error and the request’s initiating document help identify which policy needs attention.
4. Verify playback and analytics after making changes
After updating and publishing your CSP, test the video on the actual webpage where your viewers watch it.
- Confirm that the video plays in the browser and on the device where the problem occurred.
- Open the browser’s Console and Network tabs and look for CSP violations or requests marked blocked:csp.
- Confirm that video delivery and player licensing requests are not blocked.
- Check analytics requests separately: confirm that requests to Bitmovin Analytics or AWS Kinesis, as applicable to your player, are not blocked.
- Perform a new test playback and check whether the activity appears in Dacast Analytics after the normal processing delay.
If playback works but analytics remain incomplete, do not assume that CSP has been fixed. A blocked analytics request may have no visible effect on the viewer’s experience.
Updating CSP can restore the collection of future analytics events. It does not automatically recover events that the browser was previously unable to send.
5. Still experiencing issues?
If playback or analytics are still affected, contact Dacast Support and provide the webpage URL, affected browser and device, and a screenshot of any CSP errors from Developer Tools.
If possible, also provide a HAR file captured while reproducing the issue. It helps our team identify the blocked request, the relevant CSP directive, and whether the request originated from your website or the Dacast player iframe.
Please do not disable CSP or replace your entire existing policy as a troubleshooting step. Your website administrator should add only the permissions needed for your integration.













