Skip Navigation

Search

Protocols used by Engagement Engine widgets
Answer ID 13082   |   Last Review Date 11/19/2025

Why are Engagement Engine widgets loading resources over HTTP instead of HTTPS?

Environment
Chat / Engagement Engine
Oracle B2C Service
 
Issue

We noticed that sometimes Engagement Engine widgets are loading resources over HTTP instead of HTTPS, which is causing Content-Security-Policy (CSP) violations.

Resolution

Engagement Engine widgets inherit the protocol of the host page. If the embedding site permits HTTP traffic, certain widget resources may also be requested via HTTP, triggering CSP enforcement errors.

To eliminate this behavior, enforce HTTPS across the host site. Doing so ensures all Engagement Engine assets are consistently requested over HTTPS, preventing CSP violations.