Network and CSP
This page lists every host the collector contacts in each mode, and the Content Security Policy entries that allow them. No mode contacts a host that Octet or you don't run.
Hosts by mode
| Destination | Protocol | full |
lite |
passive |
|---|---|---|---|---|
Your edge, for example octet.example.com |
HTTPS POST to /v1/signals |
Yes | Yes | Yes |
| Your edge | WebSocket (wss://) to /v1/ws |
Yes | Yes | No |
lon1.octetproof.com, chs1.octetproof.com, sin1.octetproof.com |
HTTPS | Yes | No | No |
lon1.octetproof.com, chs1.octetproof.com, sin1.octetproof.com |
UDP 3478 (WebRTC) | Yes | Yes | No |
The three octetproof.com hosts are Octet network hosts the collector needs. They receive no cookies and no credentials.
Content Security Policy
The collector needs connect-src entries for your mode, and a worker-src entry in every mode. Add them to your existing policy.
full, the default:
connect-src 'self' https://octet.example.com wss://octet.example.com https://lon1.octetproof.com https://chs1.octetproof.com https://sin1.octetproof.com;
lite:
connect-src 'self' https://octet.example.com wss://octet.example.com;
passive:
connect-src 'self' https://octet.example.com;
Replace octet.example.com with your edge's hostname. List wss:// for your edge explicitly, even if the edge shares your page's origin, because some browsers don't treat 'self' as covering WebSockets.
In every mode the collector also starts a Web Worker from a blob: URL. Allow it for the best results:
worker-src blob:;
If the Worker is blocked, the collector carries on without it and never throws an error because of it. If your policy has no worker-src directive, browsers apply script-src to workers, or default-src if there is no script-src. Adding worker-src replaces that rule for workers, so also list any sources your own workers use.
If you serve octet-collector.js from your own origin, script-src 'self' covers it. The collector needs no unsafe-eval, no unsafe-inline and no frames.
WebRTC and firewalls
CSP does not control WebRTC. In full and lite mode the browser sends UDP packets to port 3478 on the three Octet network hosts. Corporate firewalls and some networks block outbound UDP. If yours might, allow outbound UDP 3478 to lon1.octetproof.com, chs1.octetproof.com and sin1.octetproof.com.
If a host is blocked
The collector still works. It leaves out any measurement it could not make, sends the rest to your edge, and never throws an error because of it. The verdict is weaker: Octet has less evidence, so fewer masked sessions reach medium or high.
The one request that must succeed is the POST to your edge. If it is blocked, ready() and verify() reject, and no verdict is produced.
Your edge
| Direction | Protocol and port | Peer |
|---|---|---|
| Inbound | TCP 443 | Browsers |
| Outbound | TCP 443 | geo.octetproof.com |
Your backend
| Direction | Protocol and port | Peer |
|---|---|---|
| Outbound | TCP 443 | geo.octetproof.com, for verdicts and the key set |