diff --git a/doc/cloud-ui-snippet.md b/doc/cloud-ui-snippet.md
index e7f0db9ae1..4787f3b9e0 100644
--- a/doc/cloud-ui-snippet.md
+++ b/doc/cloud-ui-snippet.md
@@ -29,6 +29,28 @@ included: clearing the plain variable to blank disables injection even while
a base64 value is still deployed. Everything else about the snippet is
unchanged.
+Base64 does not defeat every firewall. Some decode the value before matching,
+so they reject a base64 snippet whose decoded bytes still contain script
+markup. Deliver a bare script body (below) through one of these.
+
+## Bare script body
+
+Set the value to the script body alone — the JavaScript with no surrounding
+``, which would close the wrapper early. Because the value carries no
+``;
+ expect(injectCloudUiSnippet(html, { PAPERCLIP_MANAGED_CONFIG: "{}", PAPERCLIP_CLOUD_UI_SNIPPET: body }))
+ .toBe(html.replace("