Trusted Embed Domains for Authenticated Iframe Content

Feature overview

Organizers can now define a list of Trusted Embed Domains — external domains permitted to embed authenticated ExpoPlatform pages (such as On-Demand Sessions) via iframe. This enables secure cross-domain embedding while enforcing browser cookie policy only for whitelisted origins.

Event Setup >> General >> Settings >> Security settings

Suggested content

Trusted Embed Domains

Overview

Trusted Embed Domains allow you to specify external websites that are permitted to display authenticated ExpoPlatform content within an iframe. Only domains on this list can embed pages that require login, such as On-Demand Sessions.

Adding trusted domains

  1. Go to Event Setup >> General >> Settings.

  2. Scroll to the Security settings section.

  3. In the Trusted Embed Domains field, enter an external domain URL.

  4. Press Enter or click Add — the domain appears as a removable chip.

  5. Repeat for additional domains, then save your settings.

image-20260724-162256.png

Removing trusted domains

Click the × on any domain chip to remove it, then save.

Validation

If an invalid URL format is entered, an error message is displayed and the domain is not added.

UI helper text (verbatim)

"Add external domains allowed to embed authenticated pages (e.g. on-demand sessions) via iframe."