diff --git a/etc/csp_whitelist.xml b/etc/csp_whitelist.xml
index 27277a2..1d7b3c3 100644
--- a/etc/csp_whitelist.xml
+++ b/etc/csp_whitelist.xml
@@ -7,14 +7,16 @@
api.boldcommerce.com
api.staging.boldcommerce.com
cashier.boldcommerce.com
+ *.sandbox.braintree-api.com
+ *.braintree-api.com
- unsafe-inline
api.boldcommerce.com
api.staging.boldcommerce.com
cashier.boldcommerce.com
+ *.paypal.com
@@ -39,6 +41,7 @@
static.boldcommerce.com
+ *.paypal.com