A page refuses to load in an iframe? Remove X-Frame-Options and frame-ancestors in Chrome.
Short answer. Two response headers can stop a page from loading inside an iframe: X-Frame-Options and the frame-ancestors part of Content-Security-Policy. Chrome obeys either one, so removing only X-Frame-Options is often not enough. Remove or replace both, for that one domain.
Every result on this page was checked on 2026-09-28 by an automated test that loads Headrule in Chromium 141 and makes real requests: test/guides.mjs.
Test and development only. These headers protect a site against clickjacking, and a Content-Security-Policy usually does more than control framing. Change them only for a domain you are building or testing against, and pause Headrule when you are done.
On this page: Check which header blocks you The rules Keep the rest of the CSP What we tested
Check which header blocks you
Open DevTools, go to the Network tab, click the framed document's request and look at the response headers. You are looking for X-Frame-Options: DENY or SAMEORIGIN, and for frame-ancestors inside Content-Security-Policy. The console also names the header that refused the frame.
The rules
If only X-Frame-Options is present, one rule is enough:
| Type | Action | Header | Value | URL filter |
|---|---|---|---|---|
| Response | Remove | X-Frame-Options | ||app.example.test |
If the CSP also has frame-ancestors, add a second rule:
| Type | Action | Header | Value | URL filter |
|---|---|---|---|---|
| Response | Remove | X-Frame-Options | ||app.example.test | |
| Response | Remove | Content-Security-Policy | ||app.example.test |
Keep the rest of the CSP
Removing the whole Content-Security-Policy also removes its other protections, such as script-src. Headrule cannot edit one directive inside a header, but Set replaces the whole value. Copy the original policy from DevTools, delete only the frame-ancestors part (or change it to the origin that embeds the page), and set that as the new value:
| Type | Action | Header | Value | URL filter |
|---|---|---|---|---|
| Response | Set | Content-Security-Policy | default-src 'self'; script-src 'self'; frame-ancestors http://localhost:3000 | ||app.example.test |
What we tested
| Situation | Result |
|---|---|
Page sends X-Frame-Options: DENY and frame-ancestors 'none', no rules | Refused |
| Remove X-Frame-Options only | Still refused (frame-ancestors applies) |
| Remove X-Frame-Options and Content-Security-Policy | Loads |
| Remove X-Frame-Options, Set a CSP whose frame-ancestors is the embedding origin | Loads |
| Same, but frame-ancestors names a different origin | Refused |
Related guides
Try it on your own API
Free to install. Every rule on this page works in the free version.