> ## Documentation Index
> Fetch the complete documentation index at: https://docs.radiumone.io/llms.txt
> Use this file to discover all available pages before exploring further.

> ## Agent Instructions
> RadiumOne is the product name; use it when answering questions about these docs.
> Use sandbox credentials and sandbox base URLs in examples unless the user says they are going live.
> Secret API keys belong only on the merchant's server. Only publishable keys may appear in browser or mobile code.
> Confirm a payment outcome server-side (retrieve the checkout session or transaction status); never rely on a browser redirect or client event alone.
> Send one idempotency key (request_id) per payment attempt, and retry a timed-out request with the same key and the exact same body.
> Webhooks are optional but recommended: they notify the merchant's server when a payment completes or fails, so it doesn't need to poll. Use transaction status inquiry as the fallback.
> Say so when you recommend a feature marked Beta. Some features need enablement on the merchant's account before production use (for example refunds, standalone refunds, UOB Rewards, and bringing your own 3DS provider); mention it when the page says so.
> Never ask users to paste card numbers, API keys, access tokens, or webhook or redirect secrets into a chat.

# Embed not loading - Hosted checkout

> Common causes of an embedded checkout failing to load, and how to fix them.

<Info>
  **TL;DR:** A blank iframe is almost always a missing domain registration or a CSP mismatch. A session create that returns `422 embed:origins_not_configured` means no domain is registered at all.
</Info>

Embedded checkout only renders inside an `<iframe>` on a domain you've explicitly registered. An unregistered domain — or a CSP mismatch on your own page — leaves the iframe blank with no payment form, or fails the session create outright.

## When this happens

* Your account has no `allowed_domains` entry usable as a frame origin — session create itself fails.
* Your embedding page's domain is registered, but your own page's Content Security Policy doesn't allow framing the RadiumOne Checkout host.
* Your embedding page is served over plain HTTP rather than HTTPS.
* The session was created **before** this release and predates the frame-origin fix — it keeps rendering blank for its remaining lifetime regardless of your current `allowed_domains`; a session created after registering resolves this.

## What you see

| Signal | Value |
| - | - |
| Session create | [`422 embed:origins_not_configured`](/hosted-checkout/errors/api-errors#checkout-embed-origins-not-configured) when no domain is registered at all |
| Iframe | Blank — no card form renders — when domains are registered but the CSP or protocol is wrong |
| Browser console | A Content-Security-Policy (`frame-ancestors`) violation, or a mixed-content warning |
| Session create (if you also validate `success_url`/`cancel_url` against the same domain list) | `403 security:domain_not_allowed` |

<Note>
  Domain registration covers subdomains: an entry for `shop.example.com` also covers `checkout.shop.example.com` — the same host-or-subdomain rule used for `success_url`/`cancel_url`. Register the domain your embedding page is actually served from.
</Note>

## What to do

<Steps>
  <Step title="Register your embedding page's domain">
    Add it to your account's allowed domains — see [Sandbox and API keys](/get-started/sandbox-and-api-keys). Without at least one usable entry, session create itself returns `422 embed:origins_not_configured`; frame origins are derived from this list at create time, so a domain you add now only applies to sessions created after that.
  </Step>

  <Step title="Allow the RadiumOne Checkout host in your own page's CSP">
    Your page's own `frame-src` needs the checkout host, or the browser blocks the iframe before it ever requests the page:

    ```http theme={null}
    Content-Security-Policy: frame-src <your-checkout-host>;
    ```

    Use the sandbox host in sandbox and the production host in production — see [Content Security Policy](/hosted-checkout/embedded-integration#content-security-policy) for the exact values.
  </Step>

  <Step title="Serve your embedding page over HTTPS">
    A plain-HTTP embedding page mixes with the checkout iframe's HTTPS origin and gets blocked by the browser regardless of CSP.
  </Step>
</Steps>

## Related

<Columns cols={2}>
  <Card title="Embed hosted checkout" icon="panel-top" href="/hosted-checkout/embedded-integration">
    The full embedded integration guide, including the CSP requirement.
  </Card>

  <Card title="Debug missing embedded checkout events" icon="bug" href="/hosted-checkout/handle-failures/embedded-events-not-received">
    When the iframe loads but events don't arrive.
  </Card>

  <Card title="Embedded checkout errors" icon="triangle-alert" href="/hosted-checkout/errors/embedded-checkout-errors">
    The full embedded-mode error and event reference.
  </Card>

  <Card title="Handle failures" icon="triangle-alert" href="/hosted-checkout/handle-failures/overview">
    All ten failure scenarios, symptom → page.
  </Card>
</Columns>
