TL;DR: A blank iframe is almost always a missing domain registration or a CSP mismatch. A session create that returns
422 embed:origins_not_configured means no domain is registered at all.<iframe> on a domain you’ve explicitly registered. An unregistered domain — or a CSP mismatch on your own page — leaves the iframe blank with no payment form, or fails the session create outright.
When this happens
- Your account has no
allowed_domainsentry usable as a frame origin — session create itself fails. - Your embedding page’s domain is registered, but your own page’s Content Security Policy doesn’t allow framing the RadiumOne Checkout host.
- Your embedding page is served over plain HTTP rather than HTTPS.
- The session was created before this release and predates the frame-origin fix — it keeps rendering blank for its remaining lifetime regardless of your current
allowed_domains; a session created after registering resolves this.
What you see
Domain registration covers subdomains: an entry for
shop.example.com also covers checkout.shop.example.com — the same host-or-subdomain rule used for success_url/cancel_url. Register the domain your embedding page is actually served from.What to do
1
Register your embedding page's domain
Add it to your account’s allowed domains — see Sandbox and API keys. Without at least one usable entry, session create itself returns
422 embed:origins_not_configured; frame origins are derived from this list at create time, so a domain you add now only applies to sessions created after that.2
Allow the RadiumOne Checkout host in your own page's CSP
Your page’s own Use the sandbox host in sandbox and the production host in production — see Content Security Policy for the exact values.
frame-src needs the checkout host, or the browser blocks the iframe before it ever requests the page:3
Serve your embedding page over HTTPS
A plain-HTTP embedding page mixes with the checkout iframe’s HTTPS origin and gets blocked by the browser regardless of CSP.
Related
Embed hosted checkout
The full embedded integration guide, including the CSP requirement.
Debug missing embedded checkout events
When the iframe loads but events don’t arrive.
Embedded checkout errors
The full embedded-mode error and event reference.
Handle failures
All ten failure scenarios, symptom → page.