Pendo can't initialize in an embedded new-builder app on a custom domain (no storage in the sandbox)

My goal:
Run Pendo inside a new app builder (React) app that we embed in our product, so we get session replay and in-app guides for our external users. We embed the app with the pre-authenticated embed URL (POST /api/embed-url/external-user) under a custom domain.

Issue:
The Pendo agent loads, but pendo.initialize() throws "An exception occurred during pendo.initialize", and pendo.isReady() stays false. As far as we can tell, the app runs in a sandboxed iframe without allow-same-origin, so localStorage, sessionStorage and document.cookie all throw a SecurityError. That matches the custom-domain limits in the "Publish an app" docs. Pendo needs storage to start.

Steps I've taken to troubleshoot:

  • Opened the same app top-level instead of embedded. Same failure.
  • Tried Pendo's disablePersistence and disableCookies options. Same failure, because they don't cover sessionStorage.
  • Added Pendo's script and data domains to the app's CSP (Settings → App security). The script loads, but initialize still fails without storage.
  • When the same app was served from the *.retool.app origin, storage worked and Pendo started fine.
  • As a workaround, the app sends events to our host page with window.top.postMessage, and the host page tracks them. That covers usage analytics, but not replay or guides inside the app.

My questions:

  1. Is there a way to give an embedded new-builder app on a custom domain access to browser storage?
  2. If not, is storage access for custom-domain apps on the roadmap?
  3. Is there a recommended way to run a third-party analytics agent like Pendo inside new-builder apps?

Additional info:

Summary

Running the third-party Pendo analytics agent (for session replay and in-app guides) inside a new app builder (React) app that is embedded via a pre-authenticated embed URL under a custom domain on Retool Cloud fails, because pendo.initialize() throws and isReady() stays false — the app runs in a sandboxed iframe without allow-same-origin, so localStorage, sessionStorage, and cookies all throw SecurityError.

AI Response

*This is expected, documented behavior rather than a bug. When an app is published on a custom domain (or self-hosted), Retool deliberately runs it inside a sandboxed iframe with allow-same-origin disabled to isolate it from the Retool instance, and this removes access to localStorage, sessionStorage, IndexedDB, Cache API, and cookies. The docs explicitly note that widgets which rely on their own storage, cookies, or login session (e.g. Stripe Checkout, Calendly, reCAPTCHA) may render and then fail once storage is unavailable — the same root cause affecting Pendo, which cannot be worked around via disablePersistence/disableCookies or CSP changes since those don't restore sessionStorage. There is no setting to grant a custom-domain app access to browser storage; the documented recommendation is to route storage/auth-dependent functionality through Retool resources, and the postMessage-to-host approach already in use remains the viable path for usage analytics (though not in-app replay/guides). To keep full storage access for Pendo, serving the app from the standard .retool.app origin (where it already works) rather than a custom domain is the only configuration that avoids the sandbox restriction.

Sources

:bookmark: Publish an app | Retool Docs
Directly confirms that apps published on custom domains run in a sandboxed iframe with allow-same-origin disabled, making localStorage/sessionStorage/cookies unavailable and causing storage-dependent third-party widgets to render then fail.
:bookmark: New React App Builder Iframe CSP Settings
A solved thread where Retool staff explain the new React app builder's restrictive-by-design security, customizable CSP, and how custom-domain restrictions apply to published new-builder apps.

The Community Team is testing out a new automation. Let us know if it's helpful (or not) by leaving a :heart:, :+1:, or :-1:. Or by marking this post as the "Solution"! Let us know if you have any feedback here. :rocket:

Hi @deerawan,

Thanks for the detailed write-up! Your diagnosis is spot on. On a custom domain, new-builder apps run in a sandboxed iframe, which blocks storage and cookies. On *.retool.app, the app runs on its own origin without that sandbox, which is why Pendo worked there.

To answer your questions:

  1. Unfortunately, not today. There’s no setting that enables storage for apps on a custom domain. Right now, only cloud apps on *.retool.app have access to storage and cookies.

  2. Yes! This is on our roadmap and should be underway in the coming months. We’re working on serving custom-domain apps on their own origin, which will unlock storage and cookies, as well as hardware access like the camera and microphone.

  3. Since Pendo needs storage and cookies to start, there isn’t a supported way to run it inside the app until #2 ships. For usage analytics in the meantime, your postMessage relay to the host page is the approach we’d recommend. Once real-origin serving is available, Pendo should work in your app as-is.

Thank you Ehsu for the clear answers.