--- title: "iFrame Whitelist Configuration" slug: "iframe-whitelist" status: "new" updated: 2025-06-03T20:18:51Z published: 2025-06-03T20:18:51Z canonical: "docs.processmaker.com/iframe-whitelist" --- > ## Documentation Index > Fetch the complete documentation index at: https://docs.processmaker.com/llms.txt > Use this file to discover all available pages before exploring further. # iFrame Whitelist Configuration The **iFrame Whitelist Configuration** feature enables administrators to securely manage cross-domain embedding of ProcessMaker content. - **Embed ProcessMaker URLs into external domains**: This allows organizations to integrate ProcessMaker functionality (forms, screens, dashboards, etc.) into other websites or applications. - **Embed external URLs in** [Form Screens](/v1/docs/screens-types#form-screens) **through a Rich Text control**: Allow specific external URLs to be securely displayed within iframes in ProcessMaker Screens. > [!NOTE] > How to Embed Content in ProcessMaker? > > To learn more about adding rich content to your **Form Screens**, including text, images, and media, please refer to the [Rich Text Control](/v1/docs/rich-text-control) documentation. ### Key Features & Benefits - **Enhanced Security**: Blocks unauthorized embedding of ProcessMaker forms and screens. - **Compliance Ready**: Aligns with security protocols like CSP and X-Frame-Options. - **Configurable Controls**: Allows defining specific trusted domains for embedding. --- ## View and Manage Whitelisted Domains The **iFrame Whitelist Configuration** is available in Admin settings and enables administrators to quickly locate and manage authorized domains. Follow the steps below to manage the whitelist: 1. Ensure that you are [logged on](/v1/docs/participant-basics#log-on-to-processmaker-platform) to ProcessMaker Platform. 2. Click the **Admin** option from the top menu. The **Users** page displays. 3. Click the **Settings** icon ![](https://cdn.document360.io/2d311614-fcb7-4424-8b4c-d4d3091eebeb/Images/Documentation/Settings Icon.png) from the left sidebar to view all settings. 4. From the **Settings** panel on the left, expand the **Log-In & Auth** section. 5. Select the **iFrame Whitelist Config** section to view the following details: ![](https://cdn.document360.io/2d311614-fcb7-4424-8b4c-d4d3091eebeb/Images/Documentation/Whitelisted Domainss.png) 1. **Name:** The **Name** column displays the name of the domain. 2. **Links:** The **Links** column displays the URL parents for embedding. 6. To search for an entry, enter keywords (e.g., domain name or URL) in the **Search** bar. 7. The table will automatically filter results based on your input. 8. To manage current entries: 1. Click **Edit** to update the domain’s URL. 2. Click **Copy to Clipboard** to copy the domain’s URL. 3. Click **Clear** to delete the domain’s URL. --- ## Add a URL to the iFrame Whitelist Follow these steps, to add a URL to the **iFrame Whitelist**: 1. Ensure that you are [logged on](/v1/docs/participant-basics#log-on-to-processmaker-platform) to ProcessMaker Platform. 2. Click the **Admin** option from the top menu. The **Users** page displays. 3. Click the **Settings** icon ![](https://cdn.document360.io/2d311614-fcb7-4424-8b4c-d4d3091eebeb/Images/Documentation/Settings Icon.png) from the left sidebar to view all settings. 4. From the **Settings** panel on the left, expand the **Log-In & Auth** section. 5. Next to the **Search** bar above the list table, click **+Add URL**. ![Configuration settings for embedding ProcessMaker with site name and URL fields.](https://cdn.document360.io/2d311614-fcb7-4424-8b4c-d4d3091eebeb/Images/Documentation/Configure URL Parents for Embeddingg(1).png) 6. Add the **Site Name** and **URL** of the trusted domain allowed to embed ProcessMaker content. 7. Click **Create**. This creates a whitelist of domains authorized for embedding.