# White-listing WebSocket endpoints in \`openai/widgetCSP\`

**URL:** <https://community.openai.com/t/white-listing-websocket-endpoints-in-openai-widgetcsp/1362449>\
**Category:** ChatGPT Apps SDK\
**Tags:** apps-sdk\
**Created:** [October 14, 2025, 1:12pm UTC](https://community.openai.com/t/white-listing-websocket-endpoints-in-openai-widgetcsp/1362449 "2025-10-14T13:12:53Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![PetrBroz](https://sea2.discourse-cdn.com/openai1/user_avatar/community.openai.com/petrbroz/32/689828_2.png) [@PetrBroz](https://community.openai.com/u/PetrBroz)\
**Post date:** [October 14, 2025, 1:12pm UTC](https://community.openai.com/t/white-listing-websocket-endpoints-in-openai-widgetcsp/1362449/1 "2025-10-14T13:12:53Z")

</div>

Is it possible to white-list WebSocket endpoints under the `openai/widgetCSP` settings? The following approach doesn’t seem to be working as the `wss://…` endpoint is automatically prefixed with `https://`:

```auto
DOMAINS = [
  "https://cdn.derivative.autodesk.com",
  "wss://cdn.derivative.autodesk.com"
];

server.registerResource({
  "viewer",
  "ui://widget/viewer.html",
  {},
  async () => {
    return {
      contents: [{
        uri: "ui://widget/viewer.html",
        mimeType: "text/html",
        text: VIEWER_HTML,
        _meta: {
          "openai/widgetCSP": {
            connect_domains: DOMAINS,
            resource_domains: DOMAINS
          }
        }
      }]
    };
  }
});

```

---

<div class="post-metadata">

**Author:** ![derrick.yang122](https://avatars.discourse-cdn.com/v4/letter/d/c68b51/32.png) [@derrick.yang122](https://community.openai.com/u/derrick.yang122)\
**Post date:** [November 2, 2025, 9:11pm UTC](https://community.openai.com/t/white-listing-websocket-endpoints-in-openai-widgetcsp/1362449/2 "2025-11-02T21:11:05Z")

</div>

Hey, were you able to get an answer for this?

---

<div class="post-metadata">

**Author:** ![PetrBroz](https://sea2.discourse-cdn.com/openai1/user_avatar/community.openai.com/petrbroz/32/689828_2.png) [@PetrBroz](https://community.openai.com/u/PetrBroz)\
**Post date:** [November 3, 2025, 7:48am UTC](https://community.openai.com/t/white-listing-websocket-endpoints-in-openai-widgetcsp/1362449/3 "2025-11-03T07:48:36Z")

</div>

Unfortunately not. And I’m seeing more and more folks running into the same issue.

---

<div class="post-metadata">

**Author:** ![Dmitry\_Chyslenok](https://sea2.discourse-cdn.com/openai1/user_avatar/community.openai.com/dmitry_chyslenok/32/500366_2.png) [@Dmitry\_Chyslenok](https://community.openai.com/u/Dmitry_Chyslenok)\
**Post date:** [November 5, 2025, 8:53pm UTC](https://community.openai.com/t/white-listing-websocket-endpoints-in-openai-widgetcsp/1362449/4 "2025-11-05T20:53:56Z")

</div>

I’m asking myself a similar question. The current architecture where the frontend interacts with the server through MCP doesn’t seem ideal for building a fully functional app. I mean not just a showcase app, but a real in-chat application with full functionality. For example, I don’t understand why Zillow’s example doesn’t let you change filters within the app that feels like a basic feature. Why should I have to make an extra request and reopen the app just because I changed the search criteria? 🤷‍♂️
