diff --git a/.htaccess b/.htaccess
index c2733fadd4..3c4ba479e0 100644
--- a/.htaccess
+++ b/.htaccess
@@ -21,3 +21,9 @@
# "Not Found" body and the 404.html produced by `next build` is never used.
# The status code stays 404 either way; this only replaces the body.
ErrorDocument 404 /404.html
+
+# CSP permissions for iggy.apache.org: the kapa.ai "Ask the docs" widget and
+# the hCaptcha bot check it is configured to use. kapa.ai is approved by VP
+# Data Privacy in the ASF privacy policy:
+# https://privacy.apache.org/policies/privacy-policy-public.html#i-kapaai
+SetEnv CSP_PROJECT_DOMAINS "https://widget.kapa.ai/ https://proxy.kapa.ai/ https://kapa-widget-proxy-la7dkmplpq-uc.a.run.app/ https://metrics.kapa.ai/ https://hcaptcha.com/ https://*.hcaptcha.com/"
diff --git a/src/app/layout.tsx b/src/app/layout.tsx
index b11f6bb8f3..213979f2f4 100644
--- a/src/app/layout.tsx
+++ b/src/app/layout.tsx
@@ -137,6 +137,35 @@ _paq.push(['enableLinkTracking']);
})();`}
+ {/*
+ kapa.ai "Ask AI" widget, through the Kapa Open Source Program. kapa.ai
+ is approved in the ASF privacy policy:
+ https://privacy.apache.org/policies/privacy-policy-public.html#i-kapaai
+ The widget script loads on every page, but no question goes to kapa
+ until the visitor accepts the consent screen, and kapa's analytics
+ cookie and fingerprinting are off. The launcher is hidden; the
+ "Ask the docs" button in the navbar opens the modal.
+ */}
+