Dev GuideAPI Reference
Dev GuideAPI ReferenceUser GuideGitHubNuGetDev CommunitySubmit a ticketLog In
GitHubNuGetDev CommunitySubmit a ticket

Work with security headers

Describes the security headers settings in Optimizely Configured Commerce

If you want to increase the security of your Optimizely Configured Commerce site, you can enable HTTP security headers.



You must have the role of ISC_System or ISC_Implementer to edit these options.

You can find these settings under Administration > Settings > Site Configurations > Security Headers in the Admin Console.




Incorrectly implementing these settings could break your website.

  • Content-Security-Policy – Acts as an added layer of security to prevent cross-site scripting (XSS).