Features
Solutions
Resources
Developers
Pricing
Log inContact salesStart for free
All questions

Answers about security

Questions and answers from the Croct community about security.

securityab-testingstoryblokshopifynextjssanityaudienceshydrogenworkflowstrapicqlsetup
14

Does Croct work under a strict Content-Security-Policy?

We run a strict CSP, no unsafe-inline anywhere. The last visual testing tool we evaluated required inline script injection for its variants, which would have…

security
csp
dx
1 answer·May 26, 2026
0

After moving Croct behind our own domain, what CSP directives are still needed?

We recently completed a first-party proxying rollout for Croct requests, using the baseEndpointUrl and cidAssignerEndpointUrl options to route SDK traffic…

csp
security
ad-blockers
1 answer·Jul 2, 2026
0

CROCT_API_KEY ended up in a shared log, how do I rotate it without downtime?

On 2026-06-16 we found CROCT_API_KEY printed in a CI log from a debug step added in April. The log is internal but shared across teams, so per our policy the…

nextjs
api-key
security
cli
1 answer·Jun 17, 2026
0

Security review wants shorter-lived user tokens, what does CROCT_TOKEN_DURATION control?

Hello, our internal audit flagged all long-lived authentication artifacts in the stack, and the Croct user token came up in the list. Before I change anything…

nextjs
security
tokens
cookies
1 answer·Jul 23, 2025
  • Product
  • Component CMS
  • AB testing
  • Personalization
  • Segmentation
  • User profiles
  • All features
  • Solutions
  • Customer acquisition
  • Lead generation
  • Geo-targeting
  • Revenue growth
  • Paid search traffic
  • Social ads traffic
  • Resources
  • Documentation
  • Changelog
  • Playbooks
  • Templates
  • Blog
  • Partners
  • Company
  • Service status
  • Contact support
  • Contact sales
  • Case studies
  • Privacy policy
  • Terms of service
© Croct 2026