Allowed Domains
You can support the prevention of misuse of your key by allowing only your domain as the sole source of images.
Setup allowed domains
- in the user menu, select the API keys tab
- for the key you want to activate the function for, go to settings
- in the menu, select the Security tab
- in section Domain-based image loading restriction
write your domain (example: https://yourdomain.com/) - save the settings
Example
If set up according to the procedure, this will NOT work:
https://abcd.imagedit.io/v1/https://attacker.com/image.png
...and this WILL work:
https://abcd.imagedit.io/v1/https://yourdomain.com/image.png
If you save as blank string, that's mean ALLOW ALL.