<iframe> inside your own product, the browser refuses to display the page and logs a frame-ancestors Content Security Policy violation in the console.
Why the iframe is blocked
By default, Mintlify-hosted documentation sites send aContent-Security-Policy header with this frame-ancestors directive:
Request access for your app’s origins
You cannot changeframe-ancestors in docs.json. To request that your app’s origins be allowed, contact support. Mintlify reviews these requests case by case.
- List every origin that needs to embed your docs. Include the scheme, such as
https://app.example.com. Wildcard subdomains, such ashttps://*.example.com, are supported. - Email support@mintlify.com with your project subdomain, your documentation domain, the list of origins, and how you plan to use the embed.
- If support approves the request, reload the page in your app to verify that the iframe displays your docs.
Content-Security-Policy header, set frame-ancestors in your proxy’s policy instead. See CSP configuration.
Alternative: embed the assistant widget
If you want users to get answers from your documentation inside your app without loading the full site, embed the assistant widget instead. The widget loads from a hosted script, so it does not depend on your docs site’sframe-ancestors policy. You manage the origins allowed to load the widget in your dashboard. The widget requires a Pro or Enterprise plan. See Embed the AI assistant widget.