Skip to main content
Many auth, streaming, and blank-iframe failures come from mixing environments: staging credentials on production hosts, or a production CSP that only allows the staging SDK origin. Pick one environment per build. Align Partner Token, REST base URL, WebSocket host, SDK environment, and CSP frame-src to that environment.

Hosts by environment

Partner API REST and WebSocket

Use the same base host for REST and WebSocket in that environment. Your partnership team confirms which host and credentials apply.

Hosted SDK iframe origins (CSP frame-src)

Form filling and other hosted iframe SDKs load UI from Sukiโ€™s SDK host. If CSP blocks that origin, the iframe never loads.
SDK config uses environment: "staging" or "production" on SukiAuthManager and related clients. That value must match Partner ID, Partner Token, template IDs, and CSP host. Template IDs differ between staging and production.

Common causes

  • REST, WebSocket, and SDK hosts come from different environment configs.
  • Partner Token or Partner ID is for staging, but calls go to sdp.suki.ai (or the reverse).
  • CSP allows only https://sdk.suki.ai while the app targets staging (https://sdk.suki-stage.com), or the reverse.
  • Form filling environment is staging but form template IDs are production UUIDs (or the reverse).

Fix

1

Choose One Environment per Build

Use staging for development unless you intentionally ship production. Keep URLs and credentials together in config.
2

Align Token, Partner ID, and API Host

Get the Partner Token for that environment. Call Register and Login on the matching REST host. Send the returned sdp_suki_token only to that same host.
3

Align the WebSocket Host

Open WebSockets on the matching wss:// host (same base as REST).
4

Align SDK Environment and CSP

Set SDK environment to staging or production. Allow the matching origin in CSP frame-src. Redeploy or refresh the policy, then hard-reload.
Environment mix-ups often look like bad credentials or a blank iframe. Check host, token, partnerId / partner_id, and CSP together before you rotate secrets.

Next steps

Streaming architecture - Same REST and WebSocket base host per environment Form filling SDK error handling - CSP hosts and partner credential checks CSP blocks the SDK iframe - Allow the correct frame-src origin 401 Unauthorized or invalid Partner Token - Token validation vs wrong-host symptoms InvalidPartnerDetails during sign-in or registration - SDK credential and environment mismatches
Last modified on September 29, 2026