> ## Documentation Index
> Fetch the complete documentation index at: https://www.mintlify.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Docs site refuses to load in an iframe

> Learn why your Mintlify documentation site refuses to load inside an iframe on another domain and how to request that your app's origins be allowed.

Mintlify documentation sites block embedding in iframes on other domains by default. If you load your docs in an `<iframe>` inside your own product, the browser refuses to display the page and logs a `frame-ancestors` Content Security Policy violation in the console.

## Why the iframe is blocked

By default, Mintlify-hosted documentation sites send a `Content-Security-Policy` header with this `frame-ancestors` directive:

```text theme={null}
frame-ancestors 'self' https://dashboard.mintlify.com https://app.mintlify.com;
```

This directive only allows your documentation site itself and the Mintlify dashboard to frame your pages. Browsers block any other origin, including your app's domain. For the full default policy, see [CSP configuration](/docs/deploy/csp-configuration).

## Request access for your app's origins

You cannot change `frame-ancestors` in `docs.json`. To request that your app's origins be allowed, contact support. Mintlify reviews these requests case by case.

1. List every origin that needs to embed your docs. Include the scheme, such as `https://app.example.com`. Wildcard subdomains, such as `https://*.example.com`, are supported.
2. Email <a href="mailto:support@mintlify.com">[support@mintlify.com](mailto:support@mintlify.com)</a> with your project subdomain, your documentation domain, the list of origins, and how you plan to use the embed.
3. If support approves the request, reload the page in your app to verify that the iframe displays your docs.

Include staging or local development origins in your request if you need to test the embed outside production.

If you serve your docs through your own reverse proxy that overwrites the `Content-Security-Policy` header, set `frame-ancestors` in your proxy's policy instead. See [CSP configuration](/docs/deploy/csp-configuration).

## Alternative: embed the assistant widget

If you want users to get answers from your documentation inside your app without loading the full site, embed the assistant widget instead. The widget loads from a hosted script, so it does not depend on your docs site's `frame-ancestors` policy. You manage the origins allowed to load the widget in your dashboard. The widget requires a Pro or Enterprise plan. See [Embed the AI assistant widget](/docs/assistant/widget).


## Related topics

- [Content Security Policy (CSP) configuration](/docs/deploy/csp-configuration.md)
- [Osano](/docs/integrations/privacy/osano.md)
- [Fonts](/docs/customize/fonts.md)


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.