How to Whitelist Sites for the Asset Picker in MediaValet

In this article, you will learn how to whitelist the websites where the MediaValet Asset Picker is allowed to load.

Prerequisites

  • You must be an administrator with access to Settings → Integration Licenses.
  • You need the website URL (origin) where the Asset Picker will be embedded.

Note: The Asset Picker loads as an embedded frame on another website. A browser will only display it on sites you have whitelisted, so the picker will not appear on a new site until you complete the steps below.

Whitelist a site for a built-in integration (WordPress or Drupal)

  1. In the left-hand navigation, click Settings.
  2. Select the Integration Licenses tab.
  3. In the Integrations panel on the left, select the integration you want to manage—for example, WordPress or Drupal CMS.
  4. Select the Whitelisted Sites tab.
  1. In the Allowed Embedding Domains section, click + Add Domain.
  2. In the Add Domain dialog, enter the full address of your site in the Website URL field—for example, https://www.yourcompany.com.
  3. Click Add.

zoom_add-domain-dialog.png

Note: To approve every subdomain of a site at once, enter a wildcard such as https://*.yourcompany.com.

To stop the Asset Picker from loading on a site, return to the Whitelisted Sites tab and remove the address from the Allowed Embedding Domains list.

Whitelist a site for a custom integration

Follow these steps to embed the Asset Picker on a website that is not one of MediaValet's built-in integrations.

  1. In Settings → Integration Licenses, click + Add above the Integrations list.
  2. In the Add a New Integration dialog, type a name in the Integration Name field, then click Add.
  3. Select your new integration and open the Whitelisted Sites tab. Copy the Embed Snippet—it contains your unique App ID—and add it to the page where you want the Asset Picker:

    <iframe src="https://assetpicker.mediavalet.com?appId=YOUR-APP-ID" title="MediaValet Asset Picker"></iframe>
  4. In the Allowed Embedding Domains section, click + Add Domain, enter your website URL, and click Add.

Note: Until you whitelist at least one site for the integration, the Asset Picker embedded with that snippet will not load.

A note on monday.com

The monday.com integration does not require whitelisting. Monday.com hosts all customers under shared monday.com domains rather than customer-specific domains, so the Asset Picker is approved for monday.com automatically.

Good to know

  • Only secure (https://) sites can be whitelisted.
  • A wildcard matches one subdomain level. https://*.acme.com covers https://cms.acme.com but not https://foo.bar.acme.com.
  • Whitelisting is scoped per integration. Add a site under each integration that uses it.
  • After you add or remove a site, allow up to five minutes for the change to take effect, then refresh the embedding page.

Related Articles

If the Asset Picker does not load after you whitelist a site, confirm the exact URL—including https:// and the correct subdomain—appears under Allowed Embedding Domains for the correct integration. If the issue persists, contact MediaValet Support at support@mediavalet.com.

Was this article helpful?
0 out of 0 found this helpful