> For the complete documentation index, see [llms.txt](https://docs.nerovasystems.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.nerovasystems.com/ui-components/security-model.md).

# Embedding security model

The rules on this page are platform law, verified against the production deployment. Component builds inherit them; they are not per-component choices.

## Framing is denied by default

Every route on `app.nerovasystems.com` sends `X-Frame-Options: DENY`. The hosted connection page can never be rendered in an iframe, on any origin; this protects the provider authorization moment from clickjacking and from running in a context the provider forbids. Flows launch in popups instead; see the [host UI integration law](https://docs.nerovasystems.com/documentation/guides/host-ui-integration) for the popup rules.

The single exception is the widget route used by [embedded status widgets](https://docs.nerovasystems.com/ui-components/embedded-widgets): its responses replace the blanket denial with a `Content-Security-Policy: frame-ancestors` allow-list containing only the embedding partner's registered origins. The default remains DENY everywhere else.

## Provider UI runs top-level, always

Meta's WhatsApp Embedded Signup does not support running inside cross-origin iframes; Meta's own dialogs deny framing as well. Embedded Signup therefore always runs in a top-level window on a Meta-allow-listed domain: the Nerova hosted page in a popup, with Meta's dialog in its own `facebook.com` popup. No component changes this, and partner integrations must not attempt to frame provider UI.

## Sandboxed iframe hosts

If the partner surface that launches a popup component itself renders inside a sandboxed iframe, that iframe needs:

```html
sandbox="allow-scripts allow-popups allow-popups-to-escape-sandbox"
```

* Without `allow-popups`, the browser silently blocks the popup: the open call returns nothing and no window appears.
* Without `allow-popups-to-escape-sandbox`, the popup inherits the sandbox and the hosted page cannot run.

## Where credentials live

Provider credentials, including the merchant's Meta access token, are exchanged server-side at Nerova during the hosted flow. They never appear in the popup URL, the partner page, a widget, or any component event. Partner backends authenticate to Nerova with their API keys as usual; merchant provider credentials are never part of the partner surface area.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.nerovasystems.com/ui-components/security-model.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
