How to use iFrame with Content Security Policy? Do this: In CSP: frame-src https://www.your.iframe.website Useful links: https://observatory.mozilla.org