HeaderAudit

CSP frame-src

What your page may put in a frame.

Falls back to
child-src, then default-src
Group
Fetch directives

Detail

Controls what you embed โ€” the opposite direction from frame-ancestors, which controls who may embed you. Confusing the two is the most common CSP mistake after unsafe-inline. Payment providers, video embeds and auth widgets all need entries here.

Example

frame-src https://js.stripe.com https://www.youtube-nocookie.com

Analyse a full policy โ†’ ยท Generate one โ†’