Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
@@ -1,8 +1,10 @@
import FetchDomainChecker from "@site/src/components/FetchDomainChecker";

# HTTP Fetch

Make requests to allow-listed external domains.

Your Devvit app can make network requests to access allow-listed external domains using HTTP Fetch. This enables your app to leverage webhooks, personal servers, and other third-party integrations asynchronously across the network.
Your Devvit app can make network requests to access allow-listed external domains using HTTP Fetch. This enables your app to use approved APIs, webhooks, and other third-party integrations asynchronously across the network.

## Enabling HTTP fetch calls

Expand All @@ -28,6 +30,8 @@ Apps may request a domain to be added to the allow-list by specifying domains in

Requested domains will be submitted for review when you playtest or upload your app. Most domain requests are reviewed within **1–2 business days**, though requests with policy ambiguity may take longer. Admins may approve or deny domain requests.

<FetchDomainChecker />

Domain entries must be exact hostnames only, such as nytimes.com or wikipedia.org. These fetch requests are not allowed:

- Be specific. No using \*.example.com when you need api.example.com
Expand All @@ -54,15 +58,15 @@ Devvit Web applications have two different contexts for using fetch:
Server-side fetch allows your app to make HTTP requests to allowlisted external domains from your server-side code (e.g., API routes, server actions):

```ts title="server/index.ts"
const response = await fetch('https://example.com/api/data', {
method: 'GET',
const response = await fetch("https://example.com/api/data", {
method: "GET",
headers: {
'Content-Type': 'application/json',
"Content-Type": "application/json",
},
});

const data = await response.json();
console.log('External API response:', data);
console.log("External API response:", data);
```

### Client-side fetch
Expand Down Expand Up @@ -150,7 +154,7 @@ These domains are globally allowed and can be fetched by any app.

Allow-listed domains fall into three categories:

1. **APIs that provide data or specific services** (e.g., api.openai.com, api.wikipedia.org) \- These will be approved if they have a **publicly documented and publicly accessible API** for valid use cases, and if they adhere to the Devvit rules. Please reference our AI providers and account linking policies for common invalid use cases.
1. **APIs that provide data or specific services** (e.g., api.openai.com, api.wikipedia.org) \- These are eligible for approval if they have a **publicly documented and publicly accessible API** for a valid use case and adhere to the Devvit rules. Approval is not guaranteed and is determined during review. Please reference our AI providers and account linking policies for common invalid use cases.
2. **Limited scope cloud providers** (e.g., username.supabase.com, my-app.firebase.com) \- May be granted with exceptions. You must:
- Follow user privacy guidelines and data governance requirements
- Use an approved provider from the list below (please include your subdomain, and request for the most granular domain possible, e.g. my-app.s3.amazonaws.com)
Expand Down
2 changes: 1 addition & 1 deletion docs/capabilities/server/http-fetch-policy.md
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@

When requesting domains to be allow-listed, they fall into three categories:

1. **APIs that provide data or specific services** (e.g., `api.openai.com`, `api.wikipedia.org`) \- These will be approved if they have a **publicly documented and publicly accessible API** for valid use cases, and if they adhere to the Devvit rules. Please reference our AI providers and account linking policies for common invalid use cases.
1. **APIs that provide data or specific services** (e.g., `api.openai.com`, `api.wikipedia.org`) \- These are eligible for approval if they have a **publicly documented and publicly accessible API** for a valid use case and adhere to the Devvit rules. Approval is not guaranteed and is determined during review. Please reference our AI providers and account linking policies for common invalid use cases.

2. **Limited scope cloud providers** (e.g., `username.supabase.com`, `my-app.firebase.com`) \- May be granted with exceptions. You must:

Expand Down
6 changes: 3 additions & 3 deletions docs/guides/faq.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -175,7 +175,7 @@ Most app versions are reviewed within **1–2 business days**. New apps or versi

- **Payments**: apps using the payments capability go through additional policy review.
- **`runAs: 'USER'`**: user action permissions require explicit approval as part of the review.
- **External fetch domains**: new domain requests are reviewed separately under the same **1–2 business day** target, though requests with policy ambiguity may take longer (see [HTTP Fetch](../capabilities/http-fetch.md)).
- **External fetch domains**: new domain requests are reviewed separately under the same **1–2 business day** target, though requests with policy ambiguity may take longer (see [HTTP Fetch](../capabilities/http-fetch.mdx)).

To keep review moving:

Expand Down Expand Up @@ -454,10 +454,10 @@ Domain requests are reviewed separately from app publishing. Most domain request
To make approval go smoothly:

- Use exact hostnames only — no wildcards (`*.example.com`), no protocols (`https://`), and no paths (`api.example.com/webhooks`).
- Add a "Fetch Domains" section to your app [`README.md`](../devvit_rules.md#app-readme-requirements) listing each domain and explaining why you need it. The expected format is documented in [HTTP Fetch](../capabilities/http-fetch.md).
- Add a "Fetch Domains" section to your app [`README.md`](../devvit_rules.md#app-readme-requirements) listing each domain and explaining why you need it. The expected format is documented in [HTTP Fetch](../capabilities/http-fetch.mdx).
- Include links to your Terms and Conditions and Privacy Policy in your app details form.

Before submitting, check the [global fetch allowlist](../capabilities/http-fetch.md#global-fetch-allowlist) — if your domain is already listed there, no separate request is needed. Personal domains (e.g., `personaldomain.com`) aren't approved.
Before submitting, check the [global fetch allowlist](../capabilities/http-fetch.mdx#global-fetch-allowlist) — if your domain is already listed there, no separate request is needed. Personal domains (e.g., `personaldomain.com`) aren't approved.

</details>

Expand Down
Loading
Loading