Skip to main content
Mintlify documentation sites block embedding in iframes on other domains by default. If you load your docs in an <iframe> inside your own product, the browser refuses to display the page and logs a frame-ancestors Content Security Policy violation in the console.

Why the iframe is blocked

By default, Mintlify-hosted documentation sites send a Content-Security-Policy header with this frame-ancestors directive:
This directive only allows your documentation site itself and the Mintlify dashboard to frame your pages. Browsers block any other origin, including your app’s domain. For the full default policy, see CSP configuration.

Request access for your app’s origins

You cannot change frame-ancestors in docs.json. To request that your app’s origins be allowed, contact support. Mintlify reviews these requests case by case.
  1. List every origin that needs to embed your docs. Include the scheme, such as https://app.example.com. Wildcard subdomains, such as https://*.example.com, are supported.
  2. Email support@mintlify.com with your project subdomain, your documentation domain, the list of origins, and how you plan to use the embed.
  3. If support approves the request, reload the page in your app to verify that the iframe displays your docs.
Include staging or local development origins in your request if you need to test the embed outside production. If you serve your docs through your own reverse proxy that overwrites the Content-Security-Policy header, set frame-ancestors in your proxy’s policy instead. See CSP configuration.

Alternative: embed the assistant widget

If you want users to get answers from your documentation inside your app without loading the full site, embed the assistant widget instead. The widget loads from a hosted script, so it does not depend on your docs site’s frame-ancestors policy. You manage the origins allowed to load the widget in your dashboard. The widget requires a Pro or Enterprise plan. See Embed the AI assistant widget.