When you embed a Cornerspot form on an external website, the form only loads and submits on the domains you've authorized. This allowlist is your main lever for controlling where a form can be used: a form embedded on any origin that isn't on the list is rejected. Your own Cornerspot website, subdomain, and verified custom domain are always allowed automatically — so single-page links and website-builder embeds work with nothing added here. The allowlist is shared across your whole team, so you only need to set it up once.
How to control which sites can embed your forms
Only team admins can manage this list, and changes take effect within about five minutes (origin checks are cached). Here's the full flow — reach the allowlist, add a domain, fine-tune it, and remove it.
1. Open Publish & Share → Embed on any website
Open any form, click Publish & Share at the top, and choose Embed on any website. The embed channel includes an Allowed domains card with your Allowlisted domains — every authorized hostname lives here. (This list is shared by your whole team, so it doesn't matter which form you open.)



2. Add a hostname
Type the website's hostname into the add field — for example shop.example.com. Enter just the domain itself: no scheme (no https://) and no path.

3. Click "Add"
Select Add and the domain joins your allowlist immediately, marked Active. Forms embedded on that domain can now load and submit.


4. Fine-tune the entry
Click Edit on a domain's row to open its settings. Here you can:
- Include subdomains — match
*.example.comtoo, handy for staging and preview hosts. - Enabled — turn this off to revoke access temporarily without deleting the entry.
- Note — an internal reminder for your team; it's never shown to visitors.


5. Save your changes
Click Save changes to apply the update.

6. Remove a domain
To stop a site from running your forms, click Remove on its row and confirm in the Remove domain? dialog. Forms embedded on that domain will stop loading and submitting within about five minutes.



Good to know
- The allowlist is shared across your whole team, not tied to one form — you reach it through any form's Publish & Share → Embed on any website, and a change applies to every embedded form.
- Your own Cornerspot site, subdomain, and verified custom domain are already allowed — you only need this list for external, third-party sites.
- Add the hostname as bare text:
shop.example.com, nothttps://shop.example.com/contact. - Use Include subdomains to cover staging and preview environments without a separate entry for each.
- Prefer Enabled off over deleting if you want to revoke access but keep the entry for later.
- Changes are cached, so allow up to about five minutes for them to take effect.
