Content-Security-Policy blocks that origin in frame-src, the iframe never loads. You may see a blank container with no error code, or SUKI_FF_002 (handshake-timeout) when the iframe does not finish ready โ init-ack within 10 seconds.
Dictation SDK also loads hosted UI in an iframe. If CSP blocks that origin, the UI may not show, or the Network panel shows a blocked frame. Check frame-src / child-src and any host list your Suki contact shared.
Symptoms
A zero-height container also looks blank with no error code. Give the Form filling container an explicit height before you assume CSP is the only cause. See Form filling SDK error handling.
Allow the Form filling iframe origin
Use the origin that matches the SDK environment you configure. Staging apps that allow only production (or the reverse) still fail the handshake.
Fix
1
Confirm Environment and Origin
Match
frame-src to staging or production. Production uses https://sdk.suki.ai. Staging uses https://sdk.suki-stage.com.2
Update Content-Security-Policy
Allow that origin in
frame-src on the HTTP header (or meta policy) that applies to the page that mounts the SDK.3
Hard-Reload and Inspect
Redeploy or refresh the policy, then hard-reload. In DevTools, confirm the iframe request is not blocked and the Console has no CSP
frame-src violation.4
Retry the Session
Start Form filling again over HTTPS. If the handshake still times out, check network, ad blockers, and CSP. See Form filling SDK error handling.
Next steps
Form filling SDK error handling - Blank UI,SUKI_FF_002, and CSP checks
Form filling SDK prerequisites - Browser, layout, and frame-src origins
Form filling technical FAQs - Blank UI and CSP origins
Dictation SDK error handling - Auth and CSP related iframe issues
Form filling session returns no results - Cancel, closed, and empty structured data