Discuss and resolve questions on Liquid, JavaScript, themes, sales channels, and site speed enhancements.
Hello,
I'm currently working on an external widget that users can embed on their websites via a simple script tag. To maintain widget functionality across different pages, we utilize iframes. However, Shopify's Content Security Policy (CSP) seems to block iframes, even from the same origin, which isn't an issue on other platforms.
I understand that Shopify applies strict frame-ancestors settings in its CSP, which prevents iframes from being used. My questions are:
I've researched this issue and found several related discussions in the forum, but no clear solution. Any guidance would be appreciated.
Relevant discussions:
Thank you in advance for your help!
Same problem here did you find a solution?
Seems crazy that Shopify prevents iframes even from the same domain... This is a big problem.
Still no solution on my end either. Hoping someone from Shopify can provide guidance soon!
Learn how to build powerful custom workflows in Shopify Flow with expert guidance from ...
By Jacqui May 7, 2025Did You Know? May is named after Maia, the Roman goddess of growth and flourishing! ...
By JasonH May 2, 2025Discover opportunities to improve SEO with new guidance available from Shopify’s growth...
By Jacqui May 1, 2025