> ## Documentation Index
> Fetch the complete documentation index at: https://developer.suki.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# CSP Blocks the SDK Iframe

> Allow the Form filling SDK host in frame-src so the hosted iframe can load

Form filling runs in an iframe from Suki's SDK host. If your app's `Content-Security-Policy` blocks that origin in `frame-src`, the iframe never loads. You may see a blank container with no error code, or `SUKI_FF_002` (`handshake-timeout`) when the iframe does not finish `ready` → `init-ack` within 10 seconds.

Dictation SDK also loads hosted UI in an iframe. If CSP blocks that origin, the UI may not show, or the Network panel shows a blocked frame. Check `frame-src` / `child-src` and any host list your Suki contact shared.

## Symptoms

| Symptom | Meaning |
| :- | :- |
| Blank Form filling container, no `onError` | CSP or layout blocked the iframe before the handshake |
| `SUKI_FF_002` with reason `handshake-timeout` | Iframe did not finish `ready` → `init-ack` within 10 seconds. Check network, HTTPS, and CSP `frame-src` |
| Dictation UI never visible | Blocked iframe request or CSP violation in DevTools |

<Note>
  A zero-height container also looks blank with no error code. Give the Form filling container an explicit height before you assume CSP is the only cause. See [Form filling SDK error handling](/form-filling-sdk/guides/error-handling#blank-ui-with-no-error-code).
</Note>

## Allow the Form filling iframe origin

| Environment | Add to `frame-src` |
| :- | :- |
| Production | `https://sdk.suki.ai` |
| Staging | `https://sdk.suki-stage.com` |

Use the origin that matches the SDK environment you configure. Staging apps that allow only production (or the reverse) still fail the handshake.

## Fix

<Steps>
  <Step title="Confirm Environment and Origin">
    Match `frame-src` to staging or production. Production uses `https://sdk.suki.ai`. Staging uses `https://sdk.suki-stage.com`.
  </Step>

  <Step title="Update Content-Security-Policy">
    Allow that origin in `frame-src` on the HTTP header (or meta policy) that applies to the page that mounts the SDK.
  </Step>

  <Step title="Hard-Reload and Inspect">
    Redeploy or refresh the policy, then hard-reload. In DevTools, confirm the iframe request is not blocked and the Console has no CSP `frame-src` violation.
  </Step>

  <Step title="Retry the Session">
    Start Form filling again over HTTPS. If the handshake still times out, check network, ad blockers, and CSP. See [Form filling SDK error handling](/form-filling-sdk/guides/error-handling).
  </Step>
</Steps>

<Tip>
  If you embed inside another host (for example an EHR shell), that parent CSP can still block the iframe even when your app's local policy is correct. Update the policy the browser actually enforces on the page.
</Tip>

## Next steps

<Icon icon="file-lines" iconType="solid" /> **[Form filling SDK error handling](/form-filling-sdk/guides/error-handling)** - Blank UI, `SUKI_FF_002`, and CSP checks

<Icon icon="file-lines" iconType="solid" /> **[Form filling SDK prerequisites](/form-filling-sdk/prerequisites)** - Browser, layout, and `frame-src` origins

<Icon icon="file-lines" iconType="solid" /> **[Form filling technical FAQs](/form-filling-sdk/faqs/technical)** - Blank UI and CSP origins

<Icon icon="file-lines" iconType="solid" /> **[Dictation SDK error handling](/dictation-sdk/guides/error-handling)** - Auth and CSP related iframe issues

<Icon icon="file-lines" iconType="solid" /> **[Form filling session returns no results](/documentation/troubleshooting/form-filling-no-results)** - Cancel, closed, and empty structured data
