In this article, you will learn how to whitelist the websites where the MediaValet Asset Picker is allowed to load.
Prerequisites
- You must be an administrator with access to Settings → Integration Licenses.
- You need the website URL (origin) where the Asset Picker will be embedded.
Note: The Asset Picker loads as an embedded frame on another website. A browser will only display it on sites you have whitelisted, so the picker will not appear on a new site until you complete the steps below.
Whitelist a site for a built-in integration (WordPress or Drupal)
- In the left-hand navigation, click Settings.
- Select the Integration Licenses tab.
- In the Integrations panel on the left, select the integration you want to manage—for example, WordPress or Drupal CMS.
- Select the Whitelisted Sites tab.
- In the Allowed Embedding Domains section, click + Add Domain.
- In the Add Domain dialog, enter the full address of your site in the Website URL field—for example,
https://www.yourcompany.com. - Click Add.
Note: To approve every subdomain of a site at once, enter a wildcard such as https://*.yourcompany.com.
To stop the Asset Picker from loading on a site, return to the Whitelisted Sites tab and remove the address from the Allowed Embedding Domains list.
Whitelist a site for a custom integration
Follow these steps to embed the Asset Picker on a website that is not one of MediaValet's built-in integrations.
- In Settings → Integration Licenses, click + Add above the Integrations list.
- In the Add a New Integration dialog, type a name in the Integration Name field, then click Add.
-
Select your new integration and open the Whitelisted Sites tab. Copy the Embed Snippet—it contains your unique App ID—and add it to the page where you want the Asset Picker:
<iframe src="https://assetpicker.mediavalet.com?appId=YOUR-APP-ID" title="MediaValet Asset Picker"></iframe>
- In the Allowed Embedding Domains section, click + Add Domain, enter your website URL, and click Add.
Note: Until you whitelist at least one site for the integration, the Asset Picker embedded with that snippet will not load.
A note on monday.com
The monday.com integration does not require whitelisting. Monday.com hosts all customers under shared monday.com domains rather than customer-specific domains, so the Asset Picker is approved for monday.com automatically.
Good to know
- Only secure (
https://) sites can be whitelisted. - A wildcard matches one subdomain level.
https://*.acme.comcovershttps://cms.acme.combut nothttps://foo.bar.acme.com. - Whitelisting is scoped per integration. Add a site under each integration that uses it.
- After you add or remove a site, allow up to five minutes for the change to take effect, then refresh the embedding page.
Related Articles
- How do I use the Asset Picker in Experience Portals?
- How to Set Up the MediaValet Integration with Wordpress – MediaValet Support Center
- How to Insert MediaValet Assets into WordPress
If the Asset Picker does not load after you whitelist a site, confirm the exact URL—including https:// and the correct subdomain—appears under Allowed Embedding Domains for the correct integration. If the issue persists, contact MediaValet Support at support@mediavalet.com.