Webtzm Docs

Publish and test safely

Allowed origins are required by default for both workflow modes.

In Easy mode, add a value under Allowed domains. In Advanced mode, use Step 2.1 > Security & privacy > Allowed domains.

Enter forms.example.com Webtzm protects https://forms.example.com
  • Do not include https://, a path, query, wildcard, or port.
  • Each subdomain is separate: example.com does not allow forms.example.com.
  • A workflow accepts up to 25 unique allowed domains.
  • Webtzm blocks creation, updates, activation, and public acceptance when the domain requirement is invalid.
  • Use synthetic values with no personal, confidential, card, credential, or real customer information.

Which hostname to add

The name to add is the one the visitor's browser presents when the form submits. Usually that is the address in the visitor's address bar. On some platforms the pasted code runs somewhere else, and adding your site's own name rejects every submission.

Your own page, GitHub Pages, Blogger, Webflow, Framer Embed, self-hosted WordPress, Netlify, Cloudflare Pages, Vercel
Add the published hostname, for example www.example.com, you.github.io, or project.vercel.app. Preview deployments have their own hostnames, so add those separately or test on production.
Wix HTML iframe element
Wix runs pasted code in a frame at its own filesusr.com address. Add that hostname, which your browser's inspector shows on the frame, rather than your site's.
CodePen
Every pen runs at cdpn.io, shared by every CodePen user, so allowing it lets any pen post to the workflow. Use it for a test form and remove it before launch.
ChatGPT canvas, AI Studio and Gemini Canvas previews
The preview runs at the tool's own address, not the chat page. ChatGPT's is web-sandbox.oaiusercontent.com, shared by every ChatGPT user and behind a per-viewer network prompt; an AI Studio preview has a run.app address unique to the app, shown in its address bar; Gemini Canvas reports its own. Add that hostname to test there, then publish the page or app and add its published hostname for visitors.
Claude artifacts
The artifact blocks outside requests entirely, so nothing can be added for it. Publish the exported page on a host you own and add that hostname.
Google Sites, and WordPress.com below the Business plan
Not supported. Google Sites runs embedded code in a sandboxed frame at a Google-owned address that cannot be named here, and WordPress.com strips forms and scripts from pasted HTML on those plans.

When a site is rejected

A visitor on an unapproved site sees the rejected hostname named on the page. That hostname is also listed under Refused recently, wherever this form's allowed domains appear — Easy mode, Advanced mode, or Workspace > Manage — with a count and an Allow button. Selecting Allow adds it to the list and saves immediately, no republish required.

Something missing or wrong on this page? Tell support.