HTMLIFrameElement: sandbox property

Baseline Widely available

This feature is well established and works across many devices and browser versions. It’s been available across browsers since July 2015.

The read-only sandbox property of the HTMLIFrameElement returns a live DOMTokenList object indicating extra restrictions on the behavior of the nested content. It reflects the <iframe> element's sandbox content attribute.

Value

A live DOMTokenList object.

Although the sandbox property itself is read-only in the sense that you can't replace the DOMTokenList object, you can still assign to the sandbox property directly, which is equivalent to assigning to its value property. You can also modify the DOMTokenList object using the add(), remove(), replace(), and toggle() methods.

Examples

html
<iframe
  id="el"
  title="example"
  src="https://example.com"
  sandbox="allow-same-origin allow-scripts"></iframe>
js
const el = document.getElementById("el");
console.log(Array.from(el.sandbox)); // Output: ["allow-same-origin", "allow-scripts"]

el.sandbox = "";
console.log(Array.from(el.sandbox)); // Output: []

Specifications

Specification
HTML
# dom-iframe-sandbox

Browser compatibility

desktop mobile
Chrome
Edge
Firefox
Opera
Safari
Chrome Android
Firefox for Android
Opera Android
Safari on iOS
Samsung Internet
WebView Android
WebView on iOS
sandbox
Chrome – Full support
Chrome 5 (Release date: 2010-05-25)
footnote
footnote Before Chrome 50, this property returned the deprecated child DOMSettableTokenList instead of DOMTokenList.
Edge – Full support
Edge 12 (Release date: 2015-07-29)
footnote Full support
Firefox – Full support
Firefox 17 (Release date: 2012-11-20)
footnote
footnote Previously, the type of sandbox was a DOMString instead of a DOMSettableTokenList. This has been fixed with Firefox 29. Other browsers may still implement the property as DOMString since it was a late change in the specification.
Opera – Full support
Opera 15 (Release date: 2013-07-02)
footnote
footnote Before Opera 37, this property returned the deprecated child DOMSettableTokenList instead of DOMTokenList.
Safari – Full support
Safari 5 (Release date: 2010-06-07)
footnote Full support
Chrome Android – Full support
Chrome Android 18 (Release date: 2012-06-27)
footnote
footnote Before Chrome Android 50, this property returned the deprecated child DOMSettableTokenList instead of DOMTokenList.
Firefox for Android – Full support
Firefox for Android 17 (Release date: 2012-11-20)
footnote
footnote Previously, the type of sandbox was a DOMString instead of a DOMSettableTokenList. This has been fixed with Firefox for Android 29. Other browsers may still implement the property as DOMString since it was a late change in the specification.
Opera Android – Full support
Opera Android 14 (Release date: 2013-05-21)
footnote
footnote Before Opera Android 37, this property returned the deprecated child DOMSettableTokenList instead of DOMTokenList.
Safari on iOS – Full support
Safari on iOS 4 (Release date: 2010-06-21)
footnote Full support
Samsung Internet – Full support
Samsung Internet 1 (Release date: 2013-04-27)
footnote
footnote Before Samsung Internet 5.0, this property returned the deprecated child DOMSettableTokenList instead of DOMTokenList.
WebView Android – Full support
WebView Android 4.4 (Release date: 2013-12-09)
footnote
footnote Before WebView Android 50, this property returned the deprecated child DOMSettableTokenList instead of DOMTokenList.
WebView on iOS – Full support
WebView on iOS 4 (Release date: 2010-06-21)
footnote Full support

Legend

Tip: you can click/tap on a cell for more information.

Full support
Full support
See implementation notes.