Show external websites

Version 0.20.0. Edge-to-edge public pages, optional mobile viewports and honest static fallbacks.

1. Publish template website (iframe remains a compatible alias) with data.pages:[{url,title?,viewport?},…], layout paged or grid, and optional zero-based index. Grid is the default and shows all 1–16 pages, including a two-by-two layout for four. There is no top transport toolbar. An explicit paged layout loads the active page and uses kanvas_view_navigation control for page changes. Set viewport mobile per page for a scaled 390×844 layout; desktop is the default. Mixed viewports work in one grid.

2. Use an ordinary public HTTPS URL. Empty collections, more than sixteen pages, credentials in URLs, local/private literal addresses and executable schemes are rejected.

3. Third-party pages run in a sandbox. Their own CSP frame-ancestors and X-Frame-Options remain authoritative; KANVAS never strips headers or proxies a page to bypass embedding restrictions. Some sites also require features unavailable in the sandbox.

4. When response headers actually forbid framing, KANVAS attempts a bounded, anonymous server screenshot of the public page. It uses no viewer cookies or sign-in, blocks private networks and does not strip framing headers. Set screenshotFallback:false to disable it. Captures are labelled static with their timestamp and expire after ten minutes; they are not interactive. A frame load or screenshot never proves that a remote page rendered on a person’s screen. If capture fails, a visible original-link card shows available public title/description/preview image and explains the failure. Remote contents remain unverified. Original links remain available. Cross-origin text/DOM, search and remote controls are not accessible.

5. The visible name and primary template ID are Website and website. The iframe ID remains a compatible alias. It replaces web in current public discovery. Stored web snapshots, summaries and allowlisted embeds still render from history; exports retain their legacy data. New public submissions use website. Custom html stays script-free and does not gain iframe permission.

Example


{

  "version": 1,

  "template": "iframe",

  "data": {

    "pages": [

      {

        "url": "https://example.com/",

        "title": "Example"

      },

      {

        "url": "https://www.iana.org/help/example-domains",

        "title": "About example domains"

      }

    ],

    "index": 0

  }

}

- A tour built around your work — Agent instructions for a live, context-aware tour, never a fixed demo deck.

- Kanvas Help — Get a useful visual onto a screen, then work with it together.

- Publish your first view — One call sets up a fresh authorized workspace and returns real viewer links.

- Navigate, restore history and autoplay prepared views — Page, scroll, find, highlight and focus without republishing source data.

- Connect a private screen or open a public session — Invite a browser without confusing its address with permission.

- Compare products or offers — Line up vendors and ordered attributes with exact prices and complete URLs.

- Set numbers, units and dates — Use regional display preferences without changing exact source strings.

- Choose a template — Use the current catalog and exact field schema instead of guessing.

- Recover from a failed call — Find the real error, correct the input, and retry without duplicating work.

- Use Kanvas Help with an agent — Learn a user-chosen task with live context and real interaction.

- Read comfortably at your own pace — Independent text size, zoom and words-per-minute controls for document reading.

- Show task progress and exact logs — Accumulate real milestones, inspect dense logs and use proportional timelines.

- Invite someone to KANVAS — Create a welcome link without granting private access or sending a message.

- A live Home for your sessions — A real KANVAS display, deliberate session choices and ordinary OAuth.

- Install KANVAS and choose a receiving device — An installable web app and account-registered browser receivers.

- Read messages and technical work — Source-driven email, inbox, chat, cards, bookmarks and developer/operations views.

- Filter, sort and highlight source records — Agent-authored presentation rules, without extra filter widgets.

- Profiles, organizations and independent teams — Optional photos, clear appearance precedence and explicit group access.

- Your activity history and access audit — Query actual retained events and create charts within your current permissions.

- Live people, devices, browser windows and participant map — A live connection hierarchy, distinct from the chronological overview list.

- Explore exact JSON as a tree — A structured explorer for nested source JSON, separate from code rendering.

- Point together at the same content — Optional named semantic markers that follow text and data across screen sizes.

- Show full images, team logos and drawing backgrounds — Source-preserving media with optional per-image information.

- Report an issue at the right scope — Separate session observations, private account feedback and general service requests.

Operation reference · Machine-readable index