HTML iFrame Generator
Embed another page, video or map with a secure, responsive iframe.
HTML
<iframe src="https://www.youtube.com/embed/aqz-KE-bpKQ" title="Big Buck Bunny" width="560" height="315" style="border: 0" loading="lazy" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture" referrerpolicy="strict-origin-when-cross-origin" allowfullscreen></iframe>
HTML iFrame Generator
An <iframe> (inline frame) embeds another HTML document inside your page: a YouTube or Vimeo video, a Google Map, a booking widget, a form or a CodePen demo. The HTML iFrame Generator builds the embed code with the attributes that matter for security, performance and accessibility, and shows a live preview of the result.
Features
- Automatic embed URLs – paste a normal YouTube (
watch?v=,youtu.be, Shorts) or Vimeo link and it is converted to the embeddable player URL. - Fixed or responsive size – set width and height in pixels, or switch to a fluid 16:9 frame using the CSS
aspect-ratioproperty. - loading="lazy" – defers off-screen iframes until the user scrolls near them, saving bandwidth and speeding up the initial page load.
- allow and allowfullscreen – grant features such as autoplay, picture-in-picture or full screen.
- referrerpolicy – control how much of your URL is sent to the embedded site.
- sandbox – lock down untrusted content and re-enable only the capabilities you need.
Security notes
An iframe runs third-party code inside your page area, so only embed sources you trust. The sandbox attribute is the strongest protection: without flags the frame cannot run scripts, submit forms or open popups. Enabling both allow-scripts and allow-same-origin for a same-origin page effectively removes the sandbox, so avoid that combination.
Accessibility and SEO
Always set a meaningful title. Content inside an iframe belongs to the embedded page, not yours, so do not rely on it for SEO-relevant text. For self-hosted video files use the HTML Video Generator, and to test raw HTML safely use the HTML Viewer.
Frequently Asked Questions
Why does my iframe show a blank page or "refused to connect"?
Many sites send X-Frame-Options or a Content-Security-Policy frame-ancestors header that forbids embedding. Only pages that allow framing, such as YouTube embed URLs, maps and widgets, can be shown in an iframe.
Why do I need the embed URL for YouTube?
A normal watch URL serves the full YouTube page, which blocks framing. The embed form youtube.com/embed/VIDEO_ID is designed for iframes. The generator converts watch, youtu.be and Shorts links automatically, and Vimeo links to player.vimeo.com.
What does the sandbox attribute do?
sandbox with no value disables scripts, forms, popups and same-origin access in the embedded page. Each allow-* flag re-enables one capability. Use it for untrusted content, but avoid combining allow-scripts with allow-same-origin for content you do not control.
Is the title attribute required?
It is not required by the parser, but accessibility guidelines require every iframe to have a title describing its content so screen reader users know what the frame contains.