Custom domain destination whitelist

We have an integration in our system where it is possible as a client to create a shareable short url when the client is on an article. We have found that it is possible to get the API access token with a network inspection tool, and then submit requests to create short urls with our domain.

It seems that one solution is to restrict what destinations are possible.

Therefore I would like to be able to define a whitelist of domains that can be used as target URLs, so that we can avoid someone hijacking the API keys and create custom urls using our custom domain to destination outside our control, like https://www.attacker.com

Please authenticate to join the conversation.

Upvoters
Status

Planned

Board

💡 Feature Request

ETA
Mar 31, 2026
Date

5 months ago

Author

Ian from Saxo

Subscribe to post

Get notified by email when there are changes.