Skip to content

Pinning the tracking script (Subresource Integrity)

For strict security policies: make the browser refuse the tag if its code changes.

2 min readFor Developers

Setup → Install & domains shows an optional pinned snippet with an integrity hash and crossorigin="anonymous". The browser compares the downloaded ex.js with the hash and refuses to run it if a single byte differs.

<script async src="https://YOUR-ELEXY-DOMAIN/ex.js"
  integrity="sha384-…" crossorigin="anonymous"
  data-site="EX-XXXXXXXXXX"></script>

Good to know: Every tracker release changes the hash. A pinned tag stops collecting until you paste the new snippet, so use it only where your security policy requires it, and check the Install page after each release notice.

Related topics

Pinning the tracking script (Subresource Integrity) · Guide · Customer360