Origins
allowedOrigins is the CORS allow-list on POST /api/v1/ask. The draft default is ["*"]. Set localhost and production before you publish a live app. update_answers_draft accepts at most 20 origins.
An allowed origin lets a browser on that site call ask. It does not prove who the visitor is. A script can still replay the publishable key. Hosted ask checks the key, body size, burst limits, and the monthly allowance before it retrieves or calls a model. See limits.
Related: Configuration · Security