A customer site embedding vewo

Served from , which is a real third-party origin. Whatever happens below happens because of the domain rules, not because a header was forged.

The iframe embed

The documented snippet, unmodified. If the workspace allowlist does not include this domain, a working domain lock should refuse to play here.

What this page's own origin reports

The iframe runs on vewo.io, so the Referer vewo's API receives is vewo.io and not this page. These are the values an embed would have to forward for a lock to see the truth.

—

Webhook deliveries received here

POST /hook verifies the signature with the shared secret.

—