Updates: Reminder Content Security Policy
➡️ Exact delivery dates may vary, and brands may therefore not have immediate access to all features on the date of publication. Please contact your LivePerson account team for the exact dates on which you will have access to the features.
🚨The timing and scope of these features or functionalities remain at the sole discretion of LivePerson and are subject to change.
Web Messaging Performance
Enhancements
Final Reminder re Content-Security-Policy Updates
Action Required for brands that are utilizing a Content-Security-Policy header on their websites.
LivePerson is making important updates to the web messaging stack, which changes the protocol and domains that the scripts embedded into a brand's website use. Brands that are adding an additional layer of security by using a Content-Security-Policy (CSP) may have to adapt the CSP header to include these new domains.
This knowledge center page has been updated to reflect the latest recommendations:
https://community.liveperson.com/kb/articles/980-content-security-policy
Compared to the previous CSP, these are the changes:
- added cdn.lpsnmedia.net to the explicit lists of domains
- added https://*.liveperson.net wildcard domain for connect-src directive
LivePerson is rolling out performance enhancements and is modernizing the frontend stack. This includes loading assets from a geographically distributed content delivery network as well as deprecating JSONP as a protocol to fetch data such as account configuration. These changes require updates to the CSP, otherwise web messaging conversations can no longer be started.
Please verify if your website is using a CSP header. If not, no action is required.
In case you are leveraging a CSP, then please update the header to align with our latest recommendation which can be found on this page.
Please note the updated timeline below. These dates have been updated as of April 2025.
- April 17th - April 25th 2025: Performance enhancements (“fetch mode”) deployment rollout (what requires the brand CSP changes)
- April 17th, 2025: Small/mid-level accounts / lower environments
- April 25th, 2025: Top accounts / Enterprise environment
Any questions, please contact your LivePerson account team.