Content-Security-Policy: frame-ancestors directive

Baseline Widely available

This feature is well established and works across many devices and browser versions. It’s been available across browsers since January 2018.

The HTTP Content-Security-Policy (CSP) frame-ancestors directive specifies valid parents that may embed a page using <frame>, <iframe>, <object>, or <embed>.

Setting this directive to 'none' is similar to X-Frame-Options: deny (which is also supported in older browsers).

Note: frame-ancestors allows you to specify what parent source may embed a page. This differs from frame-src, which allows you to specify where iframes in a page may be loaded from.

Note: The frame-ancestors directive checks each ancestor. If any ancestor doesn't match, the load is cancelled. Therefore all ancestors should be allowed by the frame-ancestors directive of leaf frames when using nested frames.

CSP version 2
Directive type Navigation directive
default-src fallback No. Not setting this allows anything.
This directive is not supported in the <meta> element.

Syntax

http
Content-Security-Policy: frame-ancestors 'none';
Content-Security-Policy: frame-ancestors <source-expression-list>;

This directive may have one of the following values:

'none'

This resource may not be embedded. The single quotes are mandatory.

<source-expression-list>

A space-separated list of source expression values. This resource may be embedded if the embedder matches any of the given source expressions. For this directive, the following source expression values are applicable:

Note: The frame-ancestors directive's syntax is similar to the source list syntax accepted by other directives (e.g., child-src), but it does not fall back to the default-src setting. A policy that declares default-src 'none' still allows the resource to be embedded by anyone.

Examples

http
Content-Security-Policy: frame-ancestors 'none';

Content-Security-Policy: frame-ancestors 'self' https://www.example.org;

Content-Security-Policy: frame-ancestors 'self' https://example.org https://example.com https://store.example.com;

Specifications

Specification
Content Security Policy Level 3
# directive-frame-ancestors

Browser compatibility

desktop mobile
Chrome
Edge
Firefox
Opera
Safari
Chrome Android
Firefox for Android
Opera Android
Safari on iOS
Samsung Internet
WebView Android
WebView on iOS
frame-ancestors
Chrome – Full support
Chrome 40 (Release date: 2015-01-21)
footnote Full support
Edge – Full support
Edge 15 (Release date: 2017-04-05)
footnote Full support
Firefox – Partial support
Firefox 33 – 57 (Release date: 2014-10-14)
footnote Partial support
footnote Before Firefox 58, frame-ancestors is ignored in Content-Security-Policy-Report-Only.
Firefox – Full support
Firefox 58 (Release date: 2018-01-23)
footnote Full support
Opera – Full support
Opera 26 (Release date: 2014-12-03)
footnote Full support
Safari – Full support
Safari 10 (Release date: 2016-09-20)
footnote Full support
Chrome Android – Full support
Chrome Android 40 (Release date: 2015-01-21)
footnote Full support
Firefox for Android – Partial support
Firefox for Android 33 – 57 (Release date: 2014-10-14)
footnote Partial support
footnote Before Firefox for Android 58, frame-ancestors is ignored in Content-Security-Policy-Report-Only.
Firefox for Android – Full support
Firefox for Android 58 (Release date: 2018-01-22)
footnote Full support
Opera Android – Full support
Opera Android 27 (Release date: 2015-01-29)
footnote Full support
Safari on iOS – Full support
Safari on iOS 9.3 (Release date: 2016-03-21)
footnote Full support
Samsung Internet – Full support
Samsung Internet 4 (Release date: 2016-03-11)
footnote Full support
WebView Android – Full support
WebView Android 40 (Release date: 2015-01-21)
footnote Full support
WebView on iOS – Full support
WebView on iOS 9.3 (Release date: 2016-03-21)
footnote Full support

Legend

Tip: you can click/tap on a cell for more information.

Full support
Full support
Partial support
Partial support
Has more compatibility info.

See also