Two modes
Open your guild dashboard and find Where it works.
| Mode | How it works | Pick it when |
|---|---|---|
| Any website | Every site can use your integration. Nothing to set up. | You want maximum reach, or you're just testing. The sign-in window always shows people which site they're on. |
| Only sites I allow | A site works if it passes at least one of your rules: the site tag, your domain list or your server IPs. | You want control over where your guild shows up. Recommended for live sites. |
In both modes you can block any site, and blocks always win.
Which rule should I use?
| Your situation | Use |
|---|---|
Lots of unrelated domains or pages, like mysite.com, site.othersite.com and othersite.com/site/index.html | Site tag |
| A handful of domains you own | Domains |
| Many domains all pointing at your own servers | Server IPs |
| An npm SDK sign-in callback on your backend | Domains or Server IPs |
| A site the checker can't reach (intranet, behind a login) | Approve it in the Sites list |
You can turn on all three rules together. A site only needs to pass one.
Site tag
Your dashboard shows a one-line tag unique to your integration. Paste it inside the <head> of any page that uses your integration:
<meta name="vortex-site" content="vtxsite_..." />
When a page uses your integration for the first time, Vortex loads that page and looks for the tag. If it's there, the whole site (its domain) is allowed. There's nothing to configure per domain, so it scales to any number of sites.
How the check works
- Vortex fetches the exact page the integration is on, over HTTPS, from its own servers. The page must be publicly reachable.
- Only the start of the page is read, and redirects are only followed within the same domain.
- Allowed sites are checked again every 24 hours. If the tag is removed, the site stops working. If the check just can't connect, the site stays allowed.
- A failed check is retried after 10 minutes.
- Server-rendered tags work best. A tag added later by JavaScript won't be seen.
Which page is checked
| Type | Page checked |
|---|---|
| Embed | The page containing the iframe, as reported by the browser. See how the embed knows which site it's on. |
| CDN script | The page running the script. |
| npm SDK | The redirectUri. Callbacks usually don't return HTML, so use Domains or Server IPs instead. |
The site tag can be faked. It shows that a page says it's yours, not that it is. The tag is public, so anyone can copy it into their own site, and a site can even show the tag only to Vortex's checker and hide it from visitors. If you need to be sure, use Domains or Server IPs instead, which depend on things only you control. Otherwise, keep an eye on the Sites list and block anything you don't recognize. If the tag is being misused, Reset tag creates a new one and un-verifies every site that used the old one.
Domains
Domains you list always work, no tag or check needed. Enter one per line, up to 100:
https://yoursite.com
https://*.yoursite.com
https://partner-site.net
- Enter the origin only: scheme and host, plus a port if you use one. No paths.
https://*.yoursite.commatches every subdomain, likewww.andapp., but notyoursite.comitself. List both.- Sites must use HTTPS. For local development you can add
http://localhost:3000.
Server IPs
Any domain that points to one of your IP addresses is allowed. Vortex looks up the domain's A and AAAA records and allows it if any of them match. Enter up to 25 IPv4 or IPv6 addresses:
203.0.113.10
2001:db8::1
Only use IPs that belong to you alone. If your sites sit behind a shared host or CDN (Cloudflare, Vercel, Netlify and similar), every other site on that IP would be allowed too. Use the site tag or Domains in that case.
Sites using this
Every site that tries to use your integration shows up in the Sites using this tab, with its status, why it was allowed, when it was last seen and how many visits it has had.
| Status | Meaning |
|---|---|
| Allowed | Passed a rule (site tag, domain, server IP or any website) or you approved it. |
| Not allowed | Didn't pass any rule. The reason is shown so you can fix it. |
| Blocked | You blocked it. Blocks win over every rule and over "Any website". |
- Check a page runs the checks against any URL so you can test before going live.
- Approve allows a site the checker can't reach.
- Block stops a site from loading your integration, signing people in or refreshing their sessions.
How a site is decided
- Blocked sites are always refused.
- Sites you approved are always allowed.
- With Any website, everything else is allowed.
- Otherwise the site is allowed if it's on your domain list, points to one of your server IPs, or has your site tag.
Changing your domain list or server IPs resets the sites that relied on them, so they're checked again on their next visit.
Checking from code
The CDN script checks automatically and exposes the result as vortex.site. You can also call the endpoint yourself from the page:
const url = new URL("%ORIGIN%/api/partner/v1/site-check");
url.searchParams.set("client_id", "vtx_your_client_id");
url.searchParams.set("page", location.href);
const { allowed, reason } = await fetch(url).then((r) => r.json());