Docs/Octet Browser/Reference/Network and CSP

Network and CSP

This page lists every host the collector contacts in each mode, and the Content Security Policy entries that allow them. No mode contacts a host that Octet or you don't run.

Hosts by mode

Destination Protocol full lite passive
Your edge, for example octet.example.com HTTPS POST to /v1/signals Yes Yes Yes
Your edge WebSocket (wss://) to /v1/ws Yes Yes No
lon1.octetproof.com, chs1.octetproof.com, sin1.octetproof.com HTTPS Yes No No
lon1.octetproof.com, chs1.octetproof.com, sin1.octetproof.com UDP 3478 (WebRTC) Yes Yes No

The three octetproof.com hosts are Octet network hosts the collector needs. They receive no cookies and no credentials.

Content Security Policy

The collector needs connect-src entries for your mode, and a worker-src entry in every mode. Add them to your existing policy.

full, the default:

connect-src 'self' https://octet.example.com wss://octet.example.com https://lon1.octetproof.com https://chs1.octetproof.com https://sin1.octetproof.com;

lite:

connect-src 'self' https://octet.example.com wss://octet.example.com;

passive:

connect-src 'self' https://octet.example.com;

Replace octet.example.com with your edge's hostname. List wss:// for your edge explicitly, even if the edge shares your page's origin, because some browsers don't treat 'self' as covering WebSockets.

In every mode the collector also starts a Web Worker from a blob: URL. Allow it for the best results:

worker-src blob:;

If the Worker is blocked, the collector carries on without it and never throws an error because of it. If your policy has no worker-src directive, browsers apply script-src to workers, or default-src if there is no script-src. Adding worker-src replaces that rule for workers, so also list any sources your own workers use.

If you serve octet-collector.js from your own origin, script-src 'self' covers it. The collector needs no unsafe-eval, no unsafe-inline and no frames.

WebRTC and firewalls

CSP does not control WebRTC. In full and lite mode the browser sends UDP packets to port 3478 on the three Octet network hosts. Corporate firewalls and some networks block outbound UDP. If yours might, allow outbound UDP 3478 to lon1.octetproof.com, chs1.octetproof.com and sin1.octetproof.com.

If a host is blocked

The collector still works. It leaves out any measurement it could not make, sends the rest to your edge, and never throws an error because of it. The verdict is weaker: Octet has less evidence, so fewer masked sessions reach medium or high.

The one request that must succeed is the POST to your edge. If it is blocked, ready() and verify() reject, and no verdict is produced.

Your edge

Direction Protocol and port Peer
Inbound TCP 443 Browsers
Outbound TCP 443 geo.octetproof.com

Your backend

Direction Protocol and port Peer
Outbound TCP 443 geo.octetproof.com, for verdicts and the key set