<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Re: Refused to display 'https://xxxx.com/' in a frame because it set 'X-Frame-Options' in Community Central forum</title>
    <link>https://www.servicenow.com/community/community-central-forum/refused-to-display-https-xxxx-com-in-a-frame-because-it-set-x/m-p/3495542#M6143</link>
    <description>&lt;P&gt;&lt;a href="https://www.servicenow.com/community/user/viewprofilepage/user-id/17383"&gt;@Peter8&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;is ServiceNow instance also using same SSO as that used by 3rd party website?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":light_bulb:"&gt;💡&lt;/span&gt; If my response helped, please mark it as correct &lt;span class="lia-unicode-emoji" title=":white_heavy_check_mark:"&gt;✅&lt;/span&gt; and close the thread &lt;span class="lia-unicode-emoji" title=":locked:"&gt;🔒&lt;/span&gt;— this helps future readers find the solution faster! &lt;span class="lia-unicode-emoji" title=":folded_hands:"&gt;🙏&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 24 Feb 2026 09:58:56 GMT</pubDate>
    <dc:creator>Ankur Bawiskar</dc:creator>
    <dc:date>2026-02-24T09:58:56Z</dc:date>
    <item>
      <title>Refused to display 'https://xxxx.com/' in a frame because it set 'X-Frame-Options'</title>
      <link>https://www.servicenow.com/community/community-central-forum/refused-to-display-https-xxxx-com-in-a-frame-because-it-set-x/m-p/3495393#M6122</link>
      <description>&lt;P&gt;Hi all, I have create custom widget, embed 3rd website, but it show some error message, how can I resolved it?&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="Untitled picture.png" style="width: 999px;"&gt;&lt;img src="https://www.servicenow.com/community/image/serverpage/image-id/503231i1678C9279FB2982A/image-size/large?v=v2&amp;amp;px=999" role="button" title="Untitled picture.png" alt="Untitled picture.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Feb 2026 07:59:25 GMT</pubDate>
      <guid>https://www.servicenow.com/community/community-central-forum/refused-to-display-https-xxxx-com-in-a-frame-because-it-set-x/m-p/3495393#M6122</guid>
      <dc:creator>Peter8</dc:creator>
      <dc:date>2026-02-24T07:59:25Z</dc:date>
    </item>
    <item>
      <title>Re: Refused to display 'https://xxxx.com/' in a frame because it set 'X-Frame-Options'</title>
      <link>https://www.servicenow.com/community/community-central-forum/refused-to-display-https-xxxx-com-in-a-frame-because-it-set-x/m-p/3495432#M6125</link>
      <description>&lt;P&gt;&lt;a href="https://www.servicenow.com/community/user/viewprofilepage/user-id/17383"&gt;@Peter8&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;you can't embed external website within ServiceNow due to security reason and external website wants to avoid clickjacking attack.&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Reason being that external website must be sending an "X-Frame-Options: SAMEORIGIN" or "X-Frame-Options: DENY" in response header.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;LI-WRAPPER&gt;&lt;/LI-WRAPPER&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":light_bulb:"&gt;💡&lt;/span&gt; If my response helped, please mark it as correct &lt;span class="lia-unicode-emoji" title=":white_heavy_check_mark:"&gt;✅&lt;/span&gt; and close the thread &lt;span class="lia-unicode-emoji" title=":locked:"&gt;🔒&lt;/span&gt;— this helps future readers find the solution faster! &lt;span class="lia-unicode-emoji" title=":folded_hands:"&gt;🙏&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Feb 2026 08:41:36 GMT</pubDate>
      <guid>https://www.servicenow.com/community/community-central-forum/refused-to-display-https-xxxx-com-in-a-frame-because-it-set-x/m-p/3495432#M6125</guid>
      <dc:creator>Ankur Bawiskar</dc:creator>
      <dc:date>2026-02-24T08:41:36Z</dc:date>
    </item>
    <item>
      <title>Re: Refused to display 'https://xxxx.com/' in a frame because it set 'X-Frame-Options'</title>
      <link>https://www.servicenow.com/community/community-central-forum/refused-to-display-https-xxxx-com-in-a-frame-because-it-set-x/m-p/3495457#M6132</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://www.servicenow.com/community/user/viewprofilepage/user-id/17383"&gt;@Peter8&lt;/a&gt;&amp;nbsp;:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You are encountering the error for&amp;nbsp;&lt;STRONG&gt;clickjacking prevention from external site where&lt;/STRONG&gt;&amp;nbsp;the external website explicitly blocks other sites from embedding it in an iframe for security reasons.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here Solution could be&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Using Popup window:&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;Open the external link in a new, small browser window using&amp;nbsp;&lt;/SPAN&gt;&lt;CODE class=""&gt;window.open()&lt;/CODE&gt;&lt;/P&gt;&lt;P&gt;&lt;CODE class=""&gt;OR&amp;nbsp;&lt;/CODE&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&lt;STRONG&gt;Contact the External Website Owner:&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;The most direct solution is to contact the administrator of&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;CODE class=""&gt;&lt;A href="https://xxxx.com/" target="_blank" rel="noopener"&gt;https://xxxx.com/&lt;/A&gt;&lt;/CODE&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;and request that they configure their server to allow framing from your ServiceNow domain. This often involves adding a&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;CODE class=""&gt;Content-Security-Policy&lt;/CODE&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;(CSP)&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;CODE class=""&gt;frame-ancestors&lt;/CODE&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;directive or an&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;CODE class=""&gt;X-Frame-Options: &lt;STRONG&gt;ALLOW-FROM&lt;/STRONG&gt;&lt;/CODE&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;header specifying your instance's URL.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Feb 2026 09:05:38 GMT</pubDate>
      <guid>https://www.servicenow.com/community/community-central-forum/refused-to-display-https-xxxx-com-in-a-frame-because-it-set-x/m-p/3495457#M6132</guid>
      <dc:creator>Tanushree Maiti</dc:creator>
      <dc:date>2026-02-24T09:05:38Z</dc:date>
    </item>
    <item>
      <title>Re: Refused to display 'https://xxxx.com/' in a frame because it set 'X-Frame-Options'</title>
      <link>https://www.servicenow.com/community/community-central-forum/refused-to-display-https-xxxx-com-in-a-frame-because-it-set-x/m-p/3495519#M6138</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://www.servicenow.com/community/user/viewprofilepage/user-id/287542"&gt;@Tanushree Maiti&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do you know how can I add this in servicenow instance, for example,&amp;nbsp; I want to embed Prod to DEV, how can I add this policy in Prod instance?&lt;/P&gt;</description>
      <pubDate>Tue, 24 Feb 2026 09:43:07 GMT</pubDate>
      <guid>https://www.servicenow.com/community/community-central-forum/refused-to-display-https-xxxx-com-in-a-frame-because-it-set-x/m-p/3495519#M6138</guid>
      <dc:creator>Peter8</dc:creator>
      <dc:date>2026-02-24T09:43:07Z</dc:date>
    </item>
    <item>
      <title>Re: Refused to display 'https://xxxx.com/' in a frame because it set 'X-Frame-Options'</title>
      <link>https://www.servicenow.com/community/community-central-forum/refused-to-display-https-xxxx-com-in-a-frame-because-it-set-x/m-p/3495522#M6139</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://www.servicenow.com/community/user/viewprofilepage/user-id/265966"&gt;@Ankur Bawiskar&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do you know if there is a way for me to obtain the access token and refresh token after logging in through AAD SSO?&lt;/P&gt;</description>
      <pubDate>Tue, 24 Feb 2026 09:45:16 GMT</pubDate>
      <guid>https://www.servicenow.com/community/community-central-forum/refused-to-display-https-xxxx-com-in-a-frame-because-it-set-x/m-p/3495522#M6139</guid>
      <dc:creator>Peter8</dc:creator>
      <dc:date>2026-02-24T09:45:16Z</dc:date>
    </item>
    <item>
      <title>Re: Refused to display 'https://xxxx.com/' in a frame because it set 'X-Frame-Options'</title>
      <link>https://www.servicenow.com/community/community-central-forum/refused-to-display-https-xxxx-com-in-a-frame-because-it-set-x/m-p/3495526#M6140</link>
      <description>&lt;P&gt;&lt;a href="https://www.servicenow.com/community/user/viewprofilepage/user-id/17383"&gt;@Peter8&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;what's your exact requirement?&lt;/P&gt;
&lt;P&gt;which external website is this?&lt;/P&gt;</description>
      <pubDate>Tue, 24 Feb 2026 09:47:35 GMT</pubDate>
      <guid>https://www.servicenow.com/community/community-central-forum/refused-to-display-https-xxxx-com-in-a-frame-because-it-set-x/m-p/3495526#M6140</guid>
      <dc:creator>Ankur Bawiskar</dc:creator>
      <dc:date>2026-02-24T09:47:35Z</dc:date>
    </item>
    <item>
      <title>Re: Refused to display 'https://xxxx.com/' in a frame because it set 'X-Frame-Options'</title>
      <link>https://www.servicenow.com/community/community-central-forum/refused-to-display-https-xxxx-com-in-a-frame-because-it-set-x/m-p/3495532#M6141</link>
      <description>&lt;P&gt;Share your widget details where you have mentioned the 3rd party site&lt;/P&gt;</description>
      <pubDate>Tue, 24 Feb 2026 09:52:52 GMT</pubDate>
      <guid>https://www.servicenow.com/community/community-central-forum/refused-to-display-https-xxxx-com-in-a-frame-because-it-set-x/m-p/3495532#M6141</guid>
      <dc:creator>Tanushree Maiti</dc:creator>
      <dc:date>2026-02-24T09:52:52Z</dc:date>
    </item>
    <item>
      <title>Re: Refused to display 'https://xxxx.com/' in a frame because it set 'X-Frame-Options'</title>
      <link>https://www.servicenow.com/community/community-central-forum/refused-to-display-https-xxxx-com-in-a-frame-because-it-set-x/m-p/3495540#M6142</link>
      <description>&lt;P&gt;Hi &lt;a href="https://www.servicenow.com/community/user/viewprofilepage/user-id/265966"&gt;@Ankur Bawiskar&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I want to integrate a third-party website into SNOW. If a user of this system logs in via SSO and then accesses this page, we will find that since they have already logged in, there is no need for manual login. The SSO information will automatically log them in.&lt;/P&gt;</description>
      <pubDate>Tue, 24 Feb 2026 09:57:42 GMT</pubDate>
      <guid>https://www.servicenow.com/community/community-central-forum/refused-to-display-https-xxxx-com-in-a-frame-because-it-set-x/m-p/3495540#M6142</guid>
      <dc:creator>Peter8</dc:creator>
      <dc:date>2026-02-24T09:57:42Z</dc:date>
    </item>
    <item>
      <title>Re: Refused to display 'https://xxxx.com/' in a frame because it set 'X-Frame-Options'</title>
      <link>https://www.servicenow.com/community/community-central-forum/refused-to-display-https-xxxx-com-in-a-frame-because-it-set-x/m-p/3495542#M6143</link>
      <description>&lt;P&gt;&lt;a href="https://www.servicenow.com/community/user/viewprofilepage/user-id/17383"&gt;@Peter8&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;is ServiceNow instance also using same SSO as that used by 3rd party website?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":light_bulb:"&gt;💡&lt;/span&gt; If my response helped, please mark it as correct &lt;span class="lia-unicode-emoji" title=":white_heavy_check_mark:"&gt;✅&lt;/span&gt; and close the thread &lt;span class="lia-unicode-emoji" title=":locked:"&gt;🔒&lt;/span&gt;— this helps future readers find the solution faster! &lt;span class="lia-unicode-emoji" title=":folded_hands:"&gt;🙏&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Feb 2026 09:58:56 GMT</pubDate>
      <guid>https://www.servicenow.com/community/community-central-forum/refused-to-display-https-xxxx-com-in-a-frame-because-it-set-x/m-p/3495542#M6143</guid>
      <dc:creator>Ankur Bawiskar</dc:creator>
      <dc:date>2026-02-24T09:58:56Z</dc:date>
    </item>
    <item>
      <title>Re: Refused to display 'https://xxxx.com/' in a frame because it set 'X-Frame-Options'</title>
      <link>https://www.servicenow.com/community/community-central-forum/refused-to-display-https-xxxx-com-in-a-frame-because-it-set-x/m-p/3495546#M6144</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://www.servicenow.com/community/user/viewprofilepage/user-id/287542"&gt;@Tanushree Maiti&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Currently, I have embedded the ServiceNow Prod environment in the ServiceNow Dev environment, and then displayed this error. How can I add policies and hear in the Prod instance?&lt;/P&gt;</description>
      <pubDate>Tue, 24 Feb 2026 10:02:37 GMT</pubDate>
      <guid>https://www.servicenow.com/community/community-central-forum/refused-to-display-https-xxxx-com-in-a-frame-because-it-set-x/m-p/3495546#M6144</guid>
      <dc:creator>Peter8</dc:creator>
      <dc:date>2026-02-24T10:02:37Z</dc:date>
    </item>
    <item>
      <title>Re: Refused to display 'https://xxxx.com/' in a frame because it set 'X-Frame-Options'</title>
      <link>https://www.servicenow.com/community/community-central-forum/refused-to-display-https-xxxx-com-in-a-frame-because-it-set-x/m-p/3495548#M6145</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://www.servicenow.com/community/user/viewprofilepage/user-id/265966"&gt;@Ankur Bawiskar&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes, they are same SSO&lt;/P&gt;</description>
      <pubDate>Tue, 24 Feb 2026 10:04:28 GMT</pubDate>
      <guid>https://www.servicenow.com/community/community-central-forum/refused-to-display-https-xxxx-com-in-a-frame-because-it-set-x/m-p/3495548#M6145</guid>
      <dc:creator>Peter8</dc:creator>
      <dc:date>2026-02-24T10:04:28Z</dc:date>
    </item>
    <item>
      <title>Re: Refused to display 'https://xxxx.com/' in a frame because it set 'X-Frame-Options'</title>
      <link>https://www.servicenow.com/community/community-central-forum/refused-to-display-https-xxxx-com-in-a-frame-because-it-set-x/m-p/3495564#M6146</link>
      <description>&lt;P&gt;&lt;a href="https://www.servicenow.com/community/user/viewprofilepage/user-id/17383"&gt;@Peter8&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I still believe that external website/application won't allow this since you are reaching/connecting to their URL from within ServiceNow&lt;/P&gt;
&lt;P&gt;Please check with that team if it's allowed or not.&lt;/P&gt;
&lt;P&gt;if not then it's not feasible to achieve and embed their URL within ServiceNow.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":light_bulb:"&gt;💡&lt;/span&gt; If my response helped, please mark it as correct &lt;span class="lia-unicode-emoji" title=":white_heavy_check_mark:"&gt;✅&lt;/span&gt; and close the thread &lt;span class="lia-unicode-emoji" title=":locked:"&gt;🔒&lt;/span&gt;— this helps future readers find the solution faster! &lt;span class="lia-unicode-emoji" title=":folded_hands:"&gt;🙏&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Feb 2026 10:16:19 GMT</pubDate>
      <guid>https://www.servicenow.com/community/community-central-forum/refused-to-display-https-xxxx-com-in-a-frame-because-it-set-x/m-p/3495564#M6146</guid>
      <dc:creator>Ankur Bawiskar</dc:creator>
      <dc:date>2026-02-24T10:16:19Z</dc:date>
    </item>
    <item>
      <title>Re: Refused to display 'https://xxxx.com/' in a frame because it set 'X-Frame-Options'</title>
      <link>https://www.servicenow.com/community/community-central-forum/refused-to-display-https-xxxx-com-in-a-frame-because-it-set-x/m-p/3496298#M6156</link>
      <description>&lt;P&gt;&lt;a href="https://www.servicenow.com/community/user/viewprofilepage/user-id/17383"&gt;@Peter8&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope you are doing good.&lt;/P&gt;
&lt;P&gt;Did my reply answer your question?&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":light_bulb:"&gt;💡&lt;/span&gt; If my response helped, please mark it as correct &lt;span class="lia-unicode-emoji" title=":white_heavy_check_mark:"&gt;✅&lt;/span&gt; and close the thread &lt;span class="lia-unicode-emoji" title=":locked:"&gt;🔒&lt;/span&gt;— this helps future readers find the solution faster! &lt;span class="lia-unicode-emoji" title=":folded_hands:"&gt;🙏&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 25 Feb 2026 03:15:51 GMT</pubDate>
      <guid>https://www.servicenow.com/community/community-central-forum/refused-to-display-https-xxxx-com-in-a-frame-because-it-set-x/m-p/3496298#M6156</guid>
      <dc:creator>Ankur Bawiskar</dc:creator>
      <dc:date>2026-02-25T03:15:51Z</dc:date>
    </item>
  </channel>
</rss>

