Base44 Lets You Control Who Can Embed Your App

Base44View original changelog

Base44 added an embedding control to every app's security settings, letting builders choose whether anyone, only listed sites, or no one can embed the app in an iframe. On Enterprise plans, administrators can set a single workspace-wide embedding policy in Governance, and individual apps can only tighten it, never loosen it.

Key Takeaways

  • Three embedding modes are now available per app: anyone, only listed sites, or no one.
  • The allowlist option lets builders keep legitimate embeds on known domains while blocking everything else.
  • On Enterprise plans, admins set a single workspace-wide policy in Governance that all apps follow.
  • Apps can only be stricter than the workspace policy, never looser, which preserves the admin baseline.
  • The setting reduces exposure to unwanted iframe embedding such as clickjacking of customer-facing apps.
  • The control lives in each app's existing security settings, so no extra tooling or code changes are needed.

A New Embedding Setting for Every App

Base44 introduced a setting in each app's security options that decides who is allowed to embed that app on another website. Builders can pick one of three modes: allow anyone to embed the app, allow only a list of sites they specify, or allow no one at all. Until now, embedding was effectively open, so an app could be placed inside any third-party page. The new setting gives builders a direct way to close that door or narrow it to trusted domains.

Why It Matters

Embedding an app in an iframe is a common way to reuse a Base44 app inside a company portal, a marketing site, or a customer dashboard. It also opens the app to clickjacking-style abuse when pages the builder does not control can frame it. The allowlist mode suits the typical case, where an app should appear on a handful of known domains and nowhere else. The "no one" mode suits internal tools and apps that handle sensitive data and should only ever be opened directly.

Enterprise Governance

On Enterprise plans, workspace administrators can set one embedding policy in Governance that every app in the workspace follows. This gives security teams a consistent baseline without chasing down each app individually. Individual apps keep some flexibility: an app can adopt a stricter embedding rule than the workspace policy, but it can never be looser. For example, if the workspace allows only a list of approved sites, one app can narrow that to no embedding at all, but it cannot open itself up to anyone.

Who Benefits

Builders who ship customer-facing apps gain a simple, per-app way to protect them from unwanted framing. Enterprise administrators gain a central lever for compliance and brand-safety requirements. Teams that depend on embedding keep full control over which domains are trusted.