SandboxInjectionRule

February 19, 2026 ยท View on GitHub

HTTP header injection rules for outgoing requests matching specific domains.

Example Usage

import { SandboxInjectionRule } from "@vercel/sdk/models/sandboxinjectionrule.js";

let value: SandboxInjectionRule = {
  domain: "api.vercel.com",
  headerNames: [
    "Authorization",
    "X-API-Key",
  ],
};

Fields

FieldTypeRequiredDescriptionExample
domainstring:heavy_check_mark:The domain (or pattern) that this injection rule applies to. Supports wildcards like *.vercel.com.api.vercel.com
headerNamesstring[]:heavy_minus_sign:The names of HTTP headers that have value that will be injected for requests to this domain.[
"Authorization",
"X-API-Key"
]