What’s new
These are the docs for Metabase v0.64. Check out the docs for the current stable version, Metabase v0.63.

Allow iframes and images from other domains

Admin > Settings > Domains

By default, Metabase only lets dashboards embed iframes from a short list of popular sites, and lets images load from anywhere. Admins can allow iframes from more sites, or lock images down to trustworthy domains.

To change the web address people use to reach your Metabase, see Changing your domain name. On self-hosted Metabases, set the Site URL.

Allow iframes from a site in dashboards

Admin > Settings > Domains

If someone adds an iframe card to a dashboard and Metabase blocks it, the site isn’t on the allowlist. To allow it:

  1. Under Allowed domains for iframes in dashboards, add the site’s domain (like example.com). Separate multiple domains with commas. See How domain matching works.
  2. Click Save changes.

Only allow sites you trust. An iframe can show whatever the site serves, so anyone who can edit a dashboard can put that content in front of everyone who views it.

Metabase ships with a starter list (YouTube, Loom, Vimeo, Google Docs, and a few others). You can add to that list or clear it entirely. See How domain matching works.

You can also set the list with the MB_ALLOWED_IFRAME_HOSTS environment variable.

Restrict where images can load from

Admin > Settings > Domains

People can link to images in dashboard text cards, entity descriptions, table columns that display URLs as images, and custom visualizations. If you don’t want those images to load from just anywhere, you can restrict them to your Metabase instance plus domains you choose. You also need image restriction on before you can turn on custom visualizations, which limits where a visualization’s code can load assets from.

  1. Turn on Restrict image domains.
  2. Under Allowed domains for images, add the domains images can load from (like images.example.com). Separate multiple domains with commas. Leave the list empty to only allow images hosted by your Metabase instance. See How domain matching works.
  3. Click Save changes.

Under the hood, this sets the browser’s Content Security Policy so images can only load from your Metabase instance, the map tile server that map visualizations use, and any domains you allow. You don’t need to add the map tile server yourself.

While custom visualizations are enabled, you can’t turn off Restrict image domains. Disable custom visualizations first.

You can also set these with the MB_CSP_IMG_ENABLED and MB_CSP_IMG_ALLOWED_HOSTS environment variables.

How domain matching works

Both allowlists use the same rules. Including a subdomain is more restrictive than including the domain.

  • A domain like example.com allows the domain itself and all of its subdomains (data.example.com, docs.example.com, and so on).
  • A subdomain like data.example.com allows only that subdomain. Metabase blocks everything else, including example.com itself and its other subdomains.

So if your allowlist is:

data.example.com,
docs.example.com

Metabase only allows data.example.com and docs.example.com. It blocks example.com and every other subdomain.

Read docs for other versions of Metabase.

Was this helpful?

Thanks for your feedback!
Want to improve these docs? Propose a change.