Allowed Domains

You can support the prevention of misuse of your key by allowing only your domain as the sole source of images.

Setup allowed domains

  1. in the user menu, select the API keys tab
  2. for the key you want to activate the function for, go to settings
  3. in the menu, select the Security tab
  4. in section Domain-based image loading restriction
    write your domain (example: https://yourdomain.com/)
  5. save the settings

Example

If set up according to the procedure, this will NOT work:

https://abcd.imagedit.io/v1/https://attacker.com/image.png

...and this WILL work:

https://abcd.imagedit.io/v1/https://yourdomain.com/image.png