Publish and test safely
Allowed origins are required by default for both workflow modes.
In Easy mode, add a value under Allowed domains. In Advanced mode, use Step 2.1 > Security & privacy > Allowed domains.
forms.example.com
Webtzm protects
https://forms.example.com
- Do not include
https://, a path, query, wildcard, or port. - Each subdomain is separate:
example.comdoes not allowforms.example.com. - A workflow accepts up to 25 unique allowed domains.
- Webtzm blocks creation, updates, activation, and public acceptance when the domain requirement is invalid.
- Use synthetic values with no personal, confidential, card, credential, or real customer information.
Which hostname to add
The name to add is the one the visitor's browser presents when the form submits. Usually that is the address in the visitor's address bar. On some platforms the pasted code runs somewhere else, and adding your site's own name rejects every submission.
- Your own page, GitHub Pages, Blogger, Webflow, Framer Embed, self-hosted WordPress, Netlify, Cloudflare Pages, Vercel
- Add the published hostname, for example
www.example.com,you.github.io, orproject.vercel.app. Preview deployments have their own hostnames, so add those separately or test on production. - Wix HTML iframe element
- Wix runs pasted code in a frame at its own
filesusr.comaddress. Add that hostname, which your browser's inspector shows on the frame, rather than your site's. - CodePen
- Every pen runs at
cdpn.io, shared by every CodePen user, so allowing it lets any pen post to the workflow. Use it for a test form and remove it before launch. - ChatGPT canvas, AI Studio and Gemini Canvas previews
- The preview runs at the tool's own address, not the chat page. ChatGPT's is
web-sandbox.oaiusercontent.com, shared by every ChatGPT user and behind a per-viewer network prompt; an AI Studio preview has arun.appaddress unique to the app, shown in its address bar; Gemini Canvas reports its own. Add that hostname to test there, then publish the page or app and add its published hostname for visitors. - Claude artifacts
- The artifact blocks outside requests entirely, so nothing can be added for it. Publish the exported page on a host you own and add that hostname.
- Google Sites, and WordPress.com below the Business plan
- Not supported. Google Sites runs embedded code in a sandboxed frame at a Google-owned address that cannot be named here, and WordPress.com strips forms and scripts from pasted HTML on those plans.
When a site is rejected
A visitor on an unapproved site sees the rejected hostname named on the page. That hostname is also listed under Refused recently, wherever this form's allowed domains appear — Easy mode, Advanced mode, or Workspace > Manage — with a count and an Allow button. Selecting Allow adds it to the list and saves immediately, no republish required.