Skip to main content
TL;DR: A blank iframe is almost always a missing domain registration or a CSP mismatch. A session create that returns 422 embed:origins_not_configured means no domain is registered at all.
Embedded checkout only renders inside an <iframe> on a domain you’ve explicitly registered. An unregistered domain — or a CSP mismatch on your own page — leaves the iframe blank with no payment form, or fails the session create outright.

When this happens

  • Your account has no allowed_domains entry usable as a frame origin — session create itself fails.
  • Your embedding page’s domain is registered, but your own page’s Content Security Policy doesn’t allow framing the RadiumOne Checkout host.
  • Your embedding page is served over plain HTTP rather than HTTPS.
  • The session was created before this release and predates the frame-origin fix — it keeps rendering blank for its remaining lifetime regardless of your current allowed_domains; a session created after registering resolves this.

What you see

Domain registration covers subdomains: an entry for shop.example.com also covers checkout.shop.example.com — the same host-or-subdomain rule used for success_url/cancel_url. Register the domain your embedding page is actually served from.

What to do

1

Register your embedding page's domain

Add it to your account’s allowed domains — see Sandbox and API keys. Without at least one usable entry, session create itself returns 422 embed:origins_not_configured; frame origins are derived from this list at create time, so a domain you add now only applies to sessions created after that.
2

Allow the RadiumOne Checkout host in your own page's CSP

Your page’s own frame-src needs the checkout host, or the browser blocks the iframe before it ever requests the page:
Use the sandbox host in sandbox and the production host in production — see Content Security Policy for the exact values.
3

Serve your embedding page over HTTPS

A plain-HTTP embedding page mixes with the checkout iframe’s HTTPS origin and gets blocked by the browser regardless of CSP.

Embed hosted checkout

The full embedded integration guide, including the CSP requirement.

Debug missing embedded checkout events

When the iframe loads but events don’t arrive.

Embedded checkout errors

The full embedded-mode error and event reference.

Handle failures

All ten failure scenarios, symptom → page.
Last modified on September 15, 2026