https://pay.example.com is the origin of a payment page
at https://pay.example.com/orders/123.
Your platform owns the registration. The connected merchant receiving the
payment owns the PaymentIntent and its payment records.
For Ionic Blocks with Connect, register each platform
website once. Connected merchants with active connections and the required permissions can
use it with your platform publishable key. Direct merchant keys use the merchant’s own web domain list.
Register a website in the dashboard
- Open your platform’s Connect workspace.
- Switch to Sandbox or Live. Each mode has its own list.
- Open Payment domains and select Add domain.
- Enter the website’s origin, including
https://, and save. - Check the stored origin in the table. Register additional subdomains separately.
web_domains:read; adding or removing an origin
requires web_domains:write.
Register a website from your server
Use a platform secret key withweb_domains:write. Your platform’s Program must
allow that permission, the selected mode, and delegated API access. In
Connect → API keys, the Payment domains preset includes the read and
write permissions.
IONIC_PLATFORM_SECRET_KEY is your platform’s secret key for the target mode.
Keep it on your server.
Ionic-Account. The list belongs to your platform,
and domain requests that include the header are rejected.
To list registrations, send GET /v1/web_domains with a key that has
web_domains:read. To remove one, send DELETE /v1/web_domains/{id} with the
wd_… ID from the list and a key that has web_domains:write.
Which origins to add
Matching uses the exact origin: scheme, hostname, and port. Paths are dropped
on registration.
www.example.com and example.com are separate hosts, and
wildcards are not supported. Public sites require HTTPS; HTTP is accepted for
loopback development origins such as localhost.
Register only websites your platform operates.
Related settings
- Payment domains identify the websites used for payment collection.
- Connect redirect domains control where the authorization flow may return a user.
- Apple Pay has its own domain registration; see Apple Pay.
- Embedded checkout uses the merchant’s own domain registration.

