Errors / Blocked by the browser
Refused to frame '…' because an ancestor violates the following Content Security Policy directive: "frame-ancestors …"
A website shown inside this page does not allow being shown on this site.
An empty frame; if it was an invisible helper frame, usually nothing a visitor sees.
Why it happens
- The framed page's
Content-Security-Policy: frame-ancestorslists the sites allowed to embed it, and yours is not one of them. - Shopify stores see it for
shop.app, which only allows itself and Shopify's admin: usually a login or checkout frame meant for another context, often harmless. - Chrome also words it
Framing '…' violates the following Content Security Policy directive.
How to fix it
- If you own the framed page, add your site to its
frame-ancestors. - If you do not, it is theirs to allow; embed a URL they meant for embedding, or link to it.
Whose problem it is
Usually another company's script or site, embedded in this one.
Does your site have it?
Free, no account. We open your page and four more in a clean Chrome and list every error like this one, with the page and the click that caused it. How the free page check works.
Often seen with
- Refused to display in a frame (X-Frame-Options)The page tried to show another website inside it, and that website does not allow it.
- ERR_BLOCKED_BY_RESPONSEThe other website's own answer told the browser not to let this page use it.