Recurly Engage javascript tag

Implementation details for adding the Recurly Engage tag to your site, via tag managers or direct script injection.

Add the Recurly Engage tag to your site to initialize Engage, track user interactions, and power secure, branded checkout flows. Install it directly or through the tag manager you already use.
Available to all customers on any Recurly Engage subscription plan

Prerequisites

  • You must have Company, App Administrator, or App Member permissions in Recurly Engage.
  • You need access to modify your site's HTML or your tag manager container.

Limitations

  • If you're using a tag manager, make sure you have publish permissions.

Definition

The Recurly Engage tag is a lightweight JavaScript snippet that initializes Engage on your site. It enables tracking of user interactions and powers secure, branded checkout flows within your application.

Key benefits

Easy integrationDeploy through a popular tag manager without editing page code.
Optimal performanceLoad asynchronously or deferred to avoid delaying page rendering.
Flexible deploymentChoose from multiple tag managers, or embed the script directly.

Key details

The following tag managers are supported for convenience. You can also add the JavaScript directly to your site if you'd rather skip the tag manager.

In most cases, we recommend the defer or async script attribute to keep the tag from delaying page rendering — the Recurly Engage tag runs once the page has rendered. Reach out to your customer success manager if you have questions about specific requirements.

Content Security Policy (CSP) requirements

If your site uses a Content Security Policy, you'll need to allowlist Recurly Engage's domains so the tag can load and communicate correctly. Add the following to your configuration:

  • Script source (script-src): your unique company-specific JS tag domain.
  • Connect source (connect-src): conduit.redfast.com, to allow the necessary network traffic.
  • Additional domains to allowlist: assets.redfastlabs.com, sapi.redfast.com, and any other redfast.com or redfastlabs.com domains you encounter.

Why this is necessary

Without these entries, your browser may block the tag from executing or prevent it from sending data to our API. Common failures caused by a missing or misconfigured CSP include:

  • The tag itself failing to load or execute — blocked by script-src
  • Prompt data failing to send to or receive from Recurly's API — blocked by connect-src
  • Images or media within a prompt failing to render — blocked by img-src or media-src
  • Custom fonts or inline styles failing to apply — blocked by font-src or style-src
  • Embedded iframes within a prompt failing to load — blocked by frame-src

If you add a custom background image to a prompt, it may still fail to load even with the CSP entries above in place. This usually happens when your security settings require all image sources to be self-hosted — in that case, host the image on your own infrastructure rather than Recurly's, since Recurly's domain won't be an allowed source under those stricter policies.

NoteThis is a client-side configuration. Recurly Engage manages CORS on our end, but the CSP itself must be updated in your own site's headers or meta tags.

Did this page help you?