Skip to main content
New Voice
October 5, 2026
Question

Problem with Focused View to display identity verification

  • October 5, 2026
  • 0 replies
  • 14 views

Hello,

 

We are using embedded signing with the Focused View (DocuSign.js) for a captive recipient (ClientUserId is set) whose recipient definition includes phone-based Identity Verification (RecipientIdentityVerification with a phone_number_list input option).

 

This works correctly in our demo/sandbox environment, but fails in production. In production the Focused View iframe never renders the document, because the identity-verification step attempts to frame https://eu.verify.docusign.net/ and it is blocked by the Content Security Policy served on apps.docusign.com.

 

Browser console error:

 

Framing 'https://eu.verify.docusign.net/' violates the following Content Security Policy directive: "frame-src 'self' https://docucdn-a.akamaihd.net/ https://apps.docusign.com https://na.verify.docusign.net https://eu.docusign.net ... https://verify-d.docusign.net https://verify.docusign.net ...". The request has been blocked.

 

Key point: the frame-src allowlist in that CSP includes https://na.verify.docusign.net, https://verify.docusign.net and https://verify-d.docusign.net, but it does NOT include https://eu.verify.docusign.net. Our production account is provisioned in the EU region (base URI eu.docusign.net), so the IDV step is routed to eu.verify.docusign.net, which is not in the allowlist. This is consistent with the flow working in demo, where IDV is served from verify-d.docusign.net (which is allowlisted).

 

Request: please add https://eu.verify.docusign.net to the frame-src allowlist used by the Focused View host (apps.docusign.com) for EU-region accounts, so that phone / ID verification can load inside the embedded signing iframe.