Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Configure a CORS rule for Engagement Messenger

Configure a cross-origin resource sharing (CORS) rule to enable cross-domain requests between Engagement Messenger and your website where you want to deploy the messenger.

Before you begin

Role required: admin

You must complete the following tasks:

About this task

Use the Engagement Messenger API and your website URL to create a CORS rule.

Procedure

  1. Navigate to All > System Web Services > REST > CORS Rules.

  2. Select New.

  3. On the form, fill in the fields.

FieldDescription
NameUnique name for the CORS rule.
ApplicationApplication scope for this record.
REST API

Engagement Messenger REST API that this CORS rule applies to.

Set this field to Engagement Center API [sn_csm_ec/engagement_center_api].

Domain

Domain that sends the request to this REST API. Set this field value to the URL of the website where you want to deploy the messenger.

For example, https://www.example.com.

Max ageNumber of seconds to cache the client session. After an initial CORS request, further requests from the same client within this time do not require a preflight message. If you do not specify a value, the default value of 0 indicates that all requests require a preflight message.
HTTP MethodsAllowed HTTP methods. Enable the GET and POST methods.
HTTP HeadersComma-separated list of HTTP headers to send in the response. You can leave this field empty.
  1. Select Submit.

What to do next

Create HTTP response headers for Engagement Messenger.