These are the docs for Metabase v0.64. Check out the docs for the current stable version, Metabase v0.63.
Allow iframes and images from other domains
Admin > Settings > Domains
By default, Metabase only lets dashboards embed iframes from a short list of popular sites, and lets images load from anywhere. Admins can allow iframes from more sites, or lock images down to trustworthy domains.
To change the web address people use to reach your Metabase, see Changing your domain name. On self-hosted Metabases, set the Site URL.
Allow iframes from a site in dashboards
Admin > Settings > Domains
If someone adds an iframe card to a dashboard and Metabase blocks it, the site isn’t on the allowlist. To allow it:
- Under Allowed domains for iframes in dashboards, add the site’s domain (like
example.com). Separate multiple domains with commas. See How domain matching works. - Click Save changes.
Only allow sites you trust. An iframe can show whatever the site serves, so anyone who can edit a dashboard can put that content in front of everyone who views it.
Metabase ships with a starter list (YouTube, Loom, Vimeo, Google Docs, and a few others). You can add to that list or clear it entirely. See How domain matching works.
You can also set the list with the MB_ALLOWED_IFRAME_HOSTS environment variable.
Restrict where images can load from
Admin > Settings > Domains
People can link to images in dashboard text cards, entity descriptions, table columns that display URLs as images, and custom visualizations. If you don’t want those images to load from just anywhere, you can restrict them to your Metabase instance plus domains you choose. You also need image restriction on before you can turn on custom visualizations, which limits where a visualization’s code can load assets from.
- Turn on Restrict image domains.
- Under Allowed domains for images, add the domains images can load from (like
images.example.com). Separate multiple domains with commas. Leave the list empty to only allow images hosted by your Metabase instance. See How domain matching works. - Click Save changes.
Under the hood, this sets the browser’s Content Security Policy so images can only load from your Metabase instance, the map tile server that map visualizations use, and any domains you allow. You don’t need to add the map tile server yourself.
While custom visualizations are enabled, you can’t turn off Restrict image domains. Disable custom visualizations first.
You can also set these with the MB_CSP_IMG_ENABLED and MB_CSP_IMG_ALLOWED_HOSTS environment variables.
How domain matching works
Both allowlists use the same rules. Including a subdomain is more restrictive than including the domain.
- A domain like
example.comallows the domain itself and all of its subdomains (data.example.com,docs.example.com, and so on). - A subdomain like
data.example.comallows only that subdomain. Metabase blocks everything else, includingexample.comitself and its other subdomains.
So if your allowlist is:
data.example.com,
docs.example.com
Metabase only allows data.example.com and docs.example.com. It blocks example.com and every other subdomain.
Read docs for other versions of Metabase.