Kilo Docs

Docs / Security/ Allowed image hosts

Allowed image hosts

Updated Aug 9, 2026

Package photos on the API are not base64 in the JSON.

You send HTTPS URLs. Kilo:

  1. Checks the hostname is on your allowlist.
  2. Resolves DNS and blocks private IPs (SSRF protection).
  3. Downloads the image (size + content-type limits).
  4. Stores it on the delivery like the public form would.

Configure

Dashboard → Settings → API & Webhooks → Allowed image hosts.

One hostname per line, for example:

cdn.yourbot.com
media.yourcompany.com
public.blob.vercel-storage.com

How matching works

  • Exact host match, or
  • Any subdomain of an allowlisted host (shop.cdn.yourbot.com matches cdn.yourbot.com)

Do not use wildcards like *.public.blob.vercel-storage.com. The * is treated as a literal character and will not match.

For Vercel Blob, allowlist the base host:

public.blob.vercel-storage.com

That covers store URLs such as https://xxxxx.public.blob.vercel-storage.com/....

Localhost and private IPs are always rejected.

Checklist for AI / WhatsApp bots

  1. Host media on a domain you control (or a known CDN / Blob store).
  2. Add that hostname to the allowlist before creating deliveries (parent domain is enough for subdomains — no *).
  3. Use https:// only.
  4. Keep each image under 5MB.