Security
Allowed domains
Apps should only send data to websites your admin approved.
Your workspace keeps a list of outside websites apps may call, such as api.hubapi.com or sheets.googleapis.com.
On every deploy, the scan lists every domain the code calls. One that is not on the list is a blocking issue: the app cannot be submitted to the company directory, and a listed app is hidden from it, until the domain is allowed or the call is removed.
Asking for a domain
You do not need to do anything. When the scan meets a domain that is not on the list, a domain request is opened for your admins automatically, one per domain per workspace.
To help your admin decide, choose Ask admin to allow on the issue in the app's security review and give a reason. Admins see it next to the request.
For admins
Open Security in the admin section. Each domain request shows the domain, which apps call it, and the reasons people gave.
- Allow adds it to the list, with no redeploy. The scan re-runs on its own for every app waiting on it.
- Keep blocked closes the request. Apps must remove the call to pass the scan.
You can also manage the list directly under Policies → Allowed external domains:
| Entry | Matches |
|---|---|
api.hubapi.com | That exact host |
*.googleapis.com | Every subdomain of googleapis.com |
Enter the host only, without https:// or a path. Apps that call a domain you remove fail their next scan.