Skip to content

Platform requirements

Most platforms need nothing beyond the snippet. The sections below cover the ones that enforce a Content-Security-Policy (CSP) or restrict embeds.

If your site sends a CSP header, add the directives for the option you use.

CSP for the iframe
frame-src https://www.edgeaifoundation.org;

The iframe does not depend on any referrer setting.

Use the Embed web part with the iframe snippet.

  • The site’s HTML Field Security settings must allow embedding from www.edgeaifoundation.org. Otherwise the Embed web part refuses the iframe.
  • Register the SharePoint hostname with us, for example contoso.sharepoint.com.

If the SharePoint page is itself shown inside another app, every surrounding page must be registered too. Typical hostnames:

  • teams.microsoft.com
  • teams.cloud.microsoft
  • your SharePoint tenant hostname

Use the iframe snippet in the platform’s HTML or iframe macro. If the platform strips <script> tags, the iframe keeps a fixed height of 900 pixels. See Option A: iframe.