Iframe generator
Point it at a URL, pick the size and options, and copy a ready-to-paste iframe tag — with a live preview so you know it works.
<iframe src="https://example.com" width="100%" height="400" style="border:0;" loading="lazy"></iframe>The preview above is always sandboxed for safety; the copied code uses exactly the options you picked. Some sites (Google, GitHub, …) send headers that block being framed anywhere — if the preview stays blank, that's the site refusing, not the code.
From URL to embed code
An iframe is the simplest way to put one page inside another: the browser fetches the URL in the src attribute and renders it in an isolated box. This generator builds the tag for you — type the URL, set a size, toggle the options, and the code updates live. Paste the result anywhere HTML is accepted: a CMS block, a static site, a README rendered as HTML.
The options map straight onto attributes: loading="lazy" defers the load until the frame is near the viewport, allowfullscreen lets the framed content go fullscreen (video players need it), scrolling="no" hides scrollbars for fixed-size widgets, and sandbox restricts what the framed page may do. Borders and rounded corners are inline CSS, so they work without a stylesheet.
An iframe needs a URL to point at. If what you want to embed is an HTML file on your computer, first share the HTML file as a link, then paste that link here.
Iframe tips that save debugging time
- Always set a title attribute — screen readers announce it, and it's the only clue a non-visual user gets about what the frame contains.
- A blank preview usually means the site blocks framing with X-Frame-Options or CSP frame-ancestors. Test with the actual URL before shipping — an embed that works for YouTube's /embed/ path fails for its /watch page.
- Prefer width="100%" plus a pixel height over fixed pixel widths — a 900px iframe on a phone forces horizontal scrolling.
- When embedding third-party content you don't control, add sandbox and only re-allow what the embed needs (usually allow-scripts, sometimes allow-same-origin). It limits what a compromised embed can do.
- Iframes don't inherit your page's CSS. If the embedded page looks wrong, style changes have to happen on the framed site itself.
Frequently asked questions
What is an iframe?
An iframe (inline frame) is an HTML element that embeds another page inside yours. The browser loads the framed URL in its own isolated document, so the embedded page keeps its own styles and scripts.
Why does my iframe show up blank?
Most often the embedded site refuses to be framed. Sites send an X-Frame-Options header or a Content-Security-Policy frame-ancestors directive that tells browsers not to render them inside another page — Google, GitHub, and most login pages do this. Nothing in your iframe code can override it.
Should I set width in pixels or percent?
Use 100% for the width so the iframe fills its container and shrinks on small screens, and set a fixed pixel height. For media embeds that must keep a shape, wrap the iframe in a container with aspect-ratio CSS — our embed code generator does that for you.
What does the sandbox attribute do?
Sandbox applies extra restrictions to the framed page: with an empty value it blocks scripts, forms, popups, and same-origin access entirely, and each allow-* token re-enables one capability. Use it whenever you embed content you don't fully control.
Does loading="lazy" help performance?
Yes — the browser defers loading the framed page until the iframe scrolls near the viewport, so below-the-fold embeds stop slowing down your initial page load. It's a one-attribute win with no JavaScript needed.
Is this tool free? Does my URL get uploaded anywhere?
Free, no signup, and everything runs in your browser. The only network request is the preview iframe itself loading the URL you typed — the tool sends nothing to any server.
Related free tools
See all free tools →Built something? Put it online in seconds
host0 is the cloud for small software: bring any coding agent, build the tool only you need — like this one — and say "deploy to host0". Live at a shareable URL, no servers to run.