Embeds
Drop your pages anywhere — a blog sidebar, a post, a newsletter. Fragments are style-free (&embed=1) and resize themselves.
Embed-URL widget
The Embed URL widget puts someone else's page inside yours — a playlist, a map, a reading list from another site.
- https only. Anything else is rejected, on save and on render.
- Sandboxed. The iframe runs with sandbox="allow-scripts allow-popups" — an opaque origin, so it can't touch your page or your visitors' storage on your domain, and it can't navigate your page.
- No tracking extras. Served with a strict referrer policy; the embedded page never sees your visitors' Booklist session.
- Some sites refuse to be framed (they send X-Frame-Options) — those simply won't load, which is the site's choice.
There is no raw-HTML widget. If you need richer embeds, ask — new sandboxed widget types get added deliberately.