Show external websites
Version 0.20.0. Edge-to-edge public pages, optional mobile viewports and honest static fallbacks.
1. Publish template website (iframe remains a compatible alias) with data.pages:[{url,title?,viewport?},…], layout paged or grid, and optional zero-based index. Grid is the default and shows all 1–16 pages, including a two-by-two layout for four. There is no top transport toolbar. An explicit paged layout loads the active page and uses kanvas_view_navigation control for page changes. Set viewport mobile per page for a scaled 390×844 layout; desktop is the default. Mixed viewports work in one grid.
2. Use an ordinary public HTTPS URL. Empty collections, more than sixteen pages, credentials in URLs, local/private literal addresses and executable schemes are rejected.
3. Third-party pages run in a sandbox. Their own CSP frame-ancestors and X-Frame-Options remain authoritative; KANVAS never strips headers or proxies a page to bypass embedding restrictions. Some sites also require features unavailable in the sandbox.
4. When response headers actually forbid framing, KANVAS attempts a bounded, anonymous server screenshot of the public page. It uses no viewer cookies or sign-in, blocks private networks and does not strip framing headers. Set screenshotFallback:false to disable it. Captures are labelled static with their timestamp and expire after ten minutes; they are not interactive. A frame load or screenshot never proves that a remote page rendered on a person’s screen. If capture fails, a visible original-link card shows available public title/description/preview image and explains the failure. Remote contents remain unverified. Original links remain available. Cross-origin text/DOM, search and remote controls are not accessible.
5. The visible name and primary template ID are Website and website. The iframe ID remains a compatible alias. It replaces web in current public discovery. Stored web snapshots, summaries and allowlisted embeds still render from history; exports retain their legacy data. New public submissions use website. Custom html stays script-free and does not gain iframe permission.
Example
{
"version": 1,
"template": "iframe",
"data": {
"pages": [
{
"url": "https://example.com/",
"title": "Example"
},
{
"url": "https://www.iana.org/help/example-domains",
"title": "About example domains"
}
],
"index": 0
}
}
Related tasks
- A tour built around your work — Agent instructions for a live, context-aware tour, never a fixed demo deck.
- Kanvas Help — Get a useful visual onto a screen, then work with it together.
- Publish your first view — One call sets up a fresh authorized workspace and returns real viewer links.
- Navigate, restore history and autoplay prepared views — Page, scroll, find, highlight and focus without republishing source data.
- Connect a private screen or open a public session — Invite a browser without confusing its address with permission.
- Compare products or offers — Line up vendors and ordered attributes with exact prices and complete URLs.
- Set numbers, units and dates — Use regional display preferences without changing exact source strings.
- Choose a template — Use the current catalog and exact field schema instead of guessing.
- Recover from a failed call — Find the real error, correct the input, and retry without duplicating work.
- Use Kanvas Help with an agent — Learn a user-chosen task with live context and real interaction.
- Read comfortably at your own pace — Independent text size, zoom and words-per-minute controls for document reading.
- Show task progress and exact logs — Accumulate real milestones, inspect dense logs and use proportional timelines.
- Invite someone to KANVAS — Create a welcome link without granting private access or sending a message.
- A live Home for your sessions — A real KANVAS display, deliberate session choices and ordinary OAuth.
- Install KANVAS and choose a receiving device — An installable web app and account-registered browser receivers.
- Read messages and technical work — Source-driven email, inbox, chat, cards, bookmarks and developer/operations views.
- Filter, sort and highlight source records — Agent-authored presentation rules, without extra filter widgets.
- Profiles, organizations and independent teams — Optional photos, clear appearance precedence and explicit group access.
- Your activity history and access audit — Query actual retained events and create charts within your current permissions.
- Live people, devices, browser windows and participant map — A live connection hierarchy, distinct from the chronological overview list.
- Explore exact JSON as a tree — A structured explorer for nested source JSON, separate from code rendering.
- Point together at the same content — Optional named semantic markers that follow text and data across screen sizes.
- Show full images, team logos and drawing backgrounds — Source-preserving media with optional per-image information.
- Report an issue at the right scope — Separate session observations, private account feedback and general service requests.