X-Frame-Options
Widely Available (since 2018-01-29)
The X-Frame-Options HTTP header limits where a document may be embedded in an iframe. The X-Frame-Options: SAMEORIGIN header disallows embedding in another origin. The X-Frame-Options: DENY header disallows embedding in any context, regardless of origin.
Browser support
- Chrome 4 Released on 2010-01-25
- Chrome Android 18 Released on 2012-06-27
- Edge 12 Released on 2015-07-29
- Firefox 4 Released on 2011-03-22
- Firefox for Android 4 Released on 2011-03-29
- Safari 4 Released on 2009-06-08
- Safari on iOS 3.2 Released on 2010-04-03
MDN documentation
No MDN documentation found. You can search for the feature on MDN. If you believe that MDN has no documentation about this feature, you can open an issue on MDN's GitHub repository.Specifications
- HTML (#the-x-frame-options-header), from HTML Workstream (WHATWG).
View as JSON | Edit this feature | Report an issue | Web-features entry: source, dist