Recurly Engage javascript tag
Implementation details for adding the Recurly Engage tag to your site, via tag managers or direct script injection.
Prerequisites
- You must have Company, App Administrator, or App Member permissions in Recurly Engage.
- You need access to modify your site's HTML or your tag manager container.
Limitations
- If you're using a tag manager, make sure you have publish permissions.
Definition
Key benefits
Key details
The following tag managers are supported for convenience. You can also add the JavaScript directly to your site if you'd rather skip the tag manager.
In most cases, we recommend the defer or async script attribute to keep the tag from delaying page rendering — the Recurly Engage tag runs once the page has rendered. Reach out to your customer success manager if you have questions about specific requirements.
Content Security Policy (CSP) requirements
If your site uses a Content Security Policy, you'll need to allowlist Recurly Engage's domains so the tag can load and communicate correctly. Add the following to your configuration:
- Script source (script-src): your unique company-specific JS tag domain.
- Connect source (connect-src):
conduit.redfast.com, to allow the necessary network traffic. - Additional domains to allowlist:
assets.redfastlabs.com,sapi.redfast.com, and any otherredfast.comorredfastlabs.comdomains you encounter.
Why this is necessary
Without these entries, your browser may block the tag from executing or prevent it from sending data to our API. Common failures caused by a missing or misconfigured CSP include:
- The tag itself failing to load or execute — blocked by
script-src - Prompt data failing to send to or receive from Recurly's API — blocked by
connect-src - Images or media within a prompt failing to render — blocked by
img-srcormedia-src - Custom fonts or inline styles failing to apply — blocked by
font-srcorstyle-src - Embedded iframes within a prompt failing to load — blocked by
frame-src
If you add a custom background image to a prompt, it may still fail to load even with the CSP entries above in place. This usually happens when your security settings require all image sources to be self-hosted — in that case, host the image on your own infrastructure rather than Recurly's, since Recurly's domain won't be an allowed source under those stricter policies.
Updated 18 days ago