Learn how to install the lightweight Bug Reporter SDK, configure Content Security Policies (CSP), enforce client-side privacy masking, and integrate notifications.
Add the script tag to your website's HTML. The SDK weighs less than 20 KB and initializes silently without affecting host page runtime or performance.
<script async src="https://cdn.bugreporter.dev/widget.js" data-key="pk_your_project_key"></script>If your website uses strict Content Security Policy headers, whitelist the following origins to allow the SDK to load, send reports, and upload screenshots:
https://cdn.bugreporter.dev https://cdn.jsdelivr.netAllows loading the initial widget script and lazy-loaded screenshot modules.
https://your-domain.com https://api.cloudinary.comPermits sending diagnostic payloads and direct signed screenshot uploads.
blob: data: https://res.cloudinary.comEnables local canvas WebP generation and Cloudinary delivery.
Sensitive information is stripped in the browser before transmission, never after reaching the server.
input[type="password"] fields are replaced with solid blocks.token, jwt, secret, key) are redacted to [REDACTED] in all URLs.Add data-bug-mask="true" to any element to completely hide its content in both screenshots and click breadcrumbs:
<div data-bug-mask="true">
SSN: 000-12-3456
</div>Configure authorized domain origins in your Project Settings. Submissions originating from unauthorized hosts or domains are rejected with 403 Forbidden.
Built-in Upstash Redis sliding window enforcement limits traffic to 20 reports per 10 minutes per IP and 100 reports per hour per project to prevent denial-of-service and telemetry spam.
Forms feature hidden honeypot fields that trap automated bots and scrapers without affecting genuine user workflows.