HTML iFrame Generator

Embed another page, video or map with a secure, responsive iframe.

HTML
<iframe src="https://www.youtube.com/embed/aqz-KE-bpKQ" title="Big Buck Bunny" width="560" height="315" style="border: 0" loading="lazy" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture" referrerpolicy="strict-origin-when-cross-origin" allowfullscreen></iframe>

HTML iFrame Generator

An <iframe> (inline frame) embeds another HTML document inside your page: a YouTube or Vimeo video, a Google Map, a booking widget, a form or a CodePen demo. The HTML iFrame Generator builds the embed code with the attributes that matter for security, performance and accessibility, and shows a live preview of the result.

Features

  • Automatic embed URLs – paste a normal YouTube (watch?v=, youtu.be, Shorts) or Vimeo link and it is converted to the embeddable player URL.
  • Fixed or responsive size – set width and height in pixels, or switch to a fluid 16:9 frame using the CSS aspect-ratio property.
  • loading="lazy" – defers off-screen iframes until the user scrolls near them, saving bandwidth and speeding up the initial page load.
  • allow and allowfullscreen – grant features such as autoplay, picture-in-picture or full screen.
  • referrerpolicy – control how much of your URL is sent to the embedded site.
  • sandbox – lock down untrusted content and re-enable only the capabilities you need.

Security notes

An iframe runs third-party code inside your page area, so only embed sources you trust. The sandbox attribute is the strongest protection: without flags the frame cannot run scripts, submit forms or open popups. Enabling both allow-scripts and allow-same-origin for a same-origin page effectively removes the sandbox, so avoid that combination.

Accessibility and SEO

Always set a meaningful title. Content inside an iframe belongs to the embedded page, not yours, so do not rely on it for SEO-relevant text. For self-hosted video files use the HTML Video Generator, and to test raw HTML safely use the HTML Viewer.

Frequently Asked Questions

Many sites send X-Frame-Options or a Content-Security-Policy frame-ancestors header that forbids embedding. Only pages that allow framing, such as YouTube embed URLs, maps and widgets, can be shown in an iframe.

A normal watch URL serves the full YouTube page, which blocks framing. The embed form youtube.com/embed/VIDEO_ID is designed for iframes. The generator converts watch, youtu.be and Shorts links automatically, and Vimeo links to player.vimeo.com.

sandbox with no value disables scripts, forms, popups and same-origin access in the embedded page. Each allow-* flag re-enables one capability. Use it for untrusted content, but avoid combining allow-scripts with allow-same-origin for content you do not control.

It is not required by the parser, but accessibility guidelines require every iframe to have a title describing its content so screen reader users know what the frame contains.