x frame.
KEEP YOUR STACK. KEEP YOUR WORLD.

A tiny kit.
A bigger canvas.

X Frame checks the original website and its embedding permissions. A verified publisher player is used directly. When private browsing is enabled, other sites open as top-level pages in separate temporary browsers, with their original origins and security headers. Only browser pixels and controls cross into X Frame.

Let your site into the frame.

If you own the target, explicitly allow the X Frame origin in your response’s Content-Security-Policy. Preserve your other directives. If frame-ancestors is enforced, modern browsers use it instead of X-Frame-Options.

Content-Security-Policy: frame-ancestors 'self' https://xframe.one;

Choose this only if embedding is appropriate for your site. Do not remove DENY or SAMEORIGIN protections globally just to enable sharing. External launch works without changing these headers.

Offer an X Player Card.

Use a dedicated public embed page for interaction inside X. For an X Frame player, every ancestor must be permitted: your site, X Frame, and X/Twitter. Preserve your existing security directives and limit this policy to the embed page.

Content-Security-Policy: frame-ancestors 'self' https://xframe.one https://x.com https://*.x.com https://twitter.com https://*.twitter.com;

If your website already declares a Player Card with a separate HTTPS player URL and dimensions, X Frame verifies it and reuses that player directly. Pages that block embedding can use the private browser when enabled, with an original-site link available. X controls card display and caching.

Optional, and genuinely small.

Use our dependency-free browser module for a trusted ready signal, focus, resize messages, and user-triggered fullscreen. No framework required. The SDK does not enable execution inside X.

import { XFrame } from "https://xframe.one/xframe-sdk.js";

const frame = XFrame.init({
  parentOrigin: "https://xframe.one"
});

// Call fullscreen from a user click, when supported.
button.addEventListener("click", () => frame.fullscreen());
Download the SDK ↗

The module is provided directly. An @xframe/sdk npm package has not been published.

Know what a scan can tell you.

A header check can identify frame restrictions. HTML can reveal a viewport tag or feature references. Neither proves that login, popups, pointer lock, wallets, cookies, WebGL, or mobile controls work. Verify those in the actual browser.

Public API.

POST /api/frame                 { "url": "https://yourwebsite.com" }
GET  /api/frame/:slug            frame configuration
POST /api/frame/:slug/event      { "event": "launch" }
GET  /p/:slug                    share page and launcher
GET  /embed/:slug                eligible interactive player

Inputs are validated. Link creation has no per-user hourly quota. Remote inspection requires the protected Node inspector. Its connection pins a verified public IP for every redirect, keeps TLS verification, bounds response size and duration, and never executes returned HTML.

Read the X platform notes ↗