Site Access Docs

Developer docs

Site access

Decide which websites can use your integration, whether that's one domain or thousands of unrelated ones. The same rules cover where your embed can appear, where the CDN script runs and where people return after signing in.

Two modes

Open your guild dashboard and find Where it works.

ModeHow it worksPick it when
Any website Every site can use your integration. Nothing to set up. You want maximum reach, or you're just testing. The sign-in window always shows people which site they're on.
Only sites I allow A site works if it passes at least one of your rules: the site tag, your domain list or your server IPs. You want control over where your guild shows up. Recommended for live sites.

In both modes you can block any site, and blocks always win.

Which rule should I use?

Your situationUse
Lots of unrelated domains or pages, like mysite.com, site.othersite.com and othersite.com/site/index.htmlSite tag
A handful of domains you ownDomains
Many domains all pointing at your own serversServer IPs
An npm SDK sign-in callback on your backendDomains or Server IPs
A site the checker can't reach (intranet, behind a login)Approve it in the Sites list

You can turn on all three rules together. A site only needs to pass one.

Site tag

Your dashboard shows a one-line tag unique to your integration. Paste it inside the <head> of any page that uses your integration:

<meta name="vortex-site" content="vtxsite_..." />

When a page uses your integration for the first time, Vortex loads that page and looks for the tag. If it's there, the whole site (its domain) is allowed. There's nothing to configure per domain, so it scales to any number of sites.

How the check works

  • Vortex fetches the exact page the integration is on, over HTTPS, from its own servers. The page must be publicly reachable.
  • Only the start of the page is read, and redirects are only followed within the same domain.
  • Allowed sites are checked again every 24 hours. If the tag is removed, the site stops working. If the check just can't connect, the site stays allowed.
  • A failed check is retried after 10 minutes.
  • Server-rendered tags work best. A tag added later by JavaScript won't be seen.

Which page is checked

TypePage checked
EmbedThe page containing the iframe, as reported by the browser. See how the embed knows which site it's on.
CDN scriptThe page running the script.
npm SDKThe redirectUri. Callbacks usually don't return HTML, so use Domains or Server IPs instead.

The site tag can be faked. It shows that a page says it's yours, not that it is. The tag is public, so anyone can copy it into their own site, and a site can even show the tag only to Vortex's checker and hide it from visitors. If you need to be sure, use Domains or Server IPs instead, which depend on things only you control. Otherwise, keep an eye on the Sites list and block anything you don't recognize. If the tag is being misused, Reset tag creates a new one and un-verifies every site that used the old one.

Domains

Domains you list always work, no tag or check needed. Enter one per line, up to 100:

https://yoursite.com
https://*.yoursite.com
https://partner-site.net
  • Enter the origin only: scheme and host, plus a port if you use one. No paths.
  • https://*.yoursite.com matches every subdomain, like www. and app., but not yoursite.com itself. List both.
  • Sites must use HTTPS. For local development you can add http://localhost:3000.

Server IPs

Any domain that points to one of your IP addresses is allowed. Vortex looks up the domain's A and AAAA records and allows it if any of them match. Enter up to 25 IPv4 or IPv6 addresses:

203.0.113.10
2001:db8::1

Only use IPs that belong to you alone. If your sites sit behind a shared host or CDN (Cloudflare, Vercel, Netlify and similar), every other site on that IP would be allowed too. Use the site tag or Domains in that case.

Sites using this

Every site that tries to use your integration shows up in the Sites using this tab, with its status, why it was allowed, when it was last seen and how many visits it has had.

StatusMeaning
AllowedPassed a rule (site tag, domain, server IP or any website) or you approved it.
Not allowedDidn't pass any rule. The reason is shown so you can fix it.
BlockedYou blocked it. Blocks win over every rule and over "Any website".
  • Check a page runs the checks against any URL so you can test before going live.
  • Approve allows a site the checker can't reach.
  • Block stops a site from loading your integration, signing people in or refreshing their sessions.

How a site is decided

  1. Blocked sites are always refused.
  2. Sites you approved are always allowed.
  3. With Any website, everything else is allowed.
  4. Otherwise the site is allowed if it's on your domain list, points to one of your server IPs, or has your site tag.

Changing your domain list or server IPs resets the sites that relied on them, so they're checked again on their next visit.

Checking from code

The CDN script checks automatically and exposes the result as vortex.site. You can also call the endpoint yourself from the page:

const url = new URL("%ORIGIN%/api/partner/v1/site-check");
url.searchParams.set("client_id", "vtx_your_client_id");
url.searchParams.set("page", location.href);

const { allowed, reason } = await fetch(url).then((r) => r.json());