Client sites and domains
Save each client's website domains and, if you want, only let their videos and showcases load on those domains.
Each client site can keep a list of the website domains it belongs to. On its own, the list changes nothing: embeds keep working on any website. Turn on embed protection and the site's videos and showcases only load on those domains.
Only Owners and Admins can change site settings.
Add a website when you create a site
- Open Settings → Sites.
- Under Add a client site, type the site name.
- Optionally, type the client's website in Website (optional), like
altahomes.com. - Click Add site.
The domain shows under the site's name in the list. Embeds still work anywhere until you turn on protection.
Open a site's settings
In Settings → Sites, click Settings next to the site, or open the ⋯ menu and choose Site settings. The settings panel has:
- General: the site's name.
- Website domains: the domains embeds are allowed on when protection is on.
- Embed protection: whether to limit embeds to those domains.
- More for this site: shortcuts to Player settings, Clients, and Archive site.
Click Save changes when you're done.
Website domains
Type a domain and press Enter or click Add. You can paste a full link too: https://www.AltaHomes.com/contact is saved as altahomes.com.
example.comalso coverswww.example.com.*.example.comcovers every subdomain, likeshop.example.com. It doesn't coverexample.comitself, so add both if you need both.- Domains with accents or non-Latin letters are saved in their encoded form (
bücher.examplebecomesxn--bcher-kva.example). - Each site can have up to 20 domains.
Some entries are refused, with a message saying why:
localhostand IP addresses. Use Allow localhost for testing instead.- Wildcards on shared hosting like
*.vercel.app,*.pages.dev, or*.netlify.app. Those would let anyone's site on that host embed your media. Add the exact address, likemy-site.vercel.app, or a wildcard under it, like*.my-site.pages.dev.
Embed protection
Embed protection is off for every new site.
Turn on Only allow embeds on these domains to limit where the site's media loads:
- Videos and showcases embedded on a listed domain load as usual.
- On any other website, the embed shows "This video can't be played on this website." or "This showcase can't be shown on this website." instead.
- Dropl's own pages, like watch pages and the dashboard, always work.
- Inside a showcase, each video still follows its own embed setting. Videos use the site's setting unless they were given their own.
If protection is on and the list is empty, the panel warns you: embeds won't load on any website until you add a domain.
Testing on your computer
Turn on Allow localhost for testing to let embeds load on localhost, 127.0.0.1, and [::1] on any port while you build the site. It only matters while protection is on. Turn it off when the site goes live if you don't need it.
For preview deployments, add the preview's exact address (or a wildcard under your own project, like *.my-site.pages.dev) to Website domains.
What protection doesn't do
Protection checks which website a browser says it's loading the embed from. That stops other websites from embedding your client's media. It isn't a password: anyone who can watch a video can still find a way to save it. To limit who can watch, use a video's Private or password settings.
Embeds inside sandboxed frames, or pages opened from a file on your computer, don't say which website they're on, so they're blocked while protection is on.
Related
- Getting started
- Public API:
POST /v1/sitestakes the samedomainfield. - Set up with AI

