Session length
Currently, using a valid embed URL will create an embed session that can be configured to last between 0-576 hours. That embed session will be unusable after the configured expiry. Visiting a new, valid embed SSO URL at any time will create a new session.Default iframe restrictions
By default, iframes restrict access to certain functionality that could post a security risk, such as copying or using the mircophone. However, you can allow your users to use these features by including them in your iframe declarations. See Enabling iframe-restricted functionality for embedded instances for more information.Keyboard shortcuts
Keyboard shortcuts are not currently supported in embedded Omni instances.Third-party cookies
Omni uses cookies to manage authentication sessions. When embedded in iframes, some older browsers treat these as third-party cookies and block them by default, which prevents access to Omni content. On modern browsers, Omni supports CHIPS (Cookies Having Independent Partitioned State), which allows embedded content to authenticate automatically without requiring user action. Omni detects CHIPS support and handles authentication seamlessly.Chrome 113 and older in Incognito mode - Explicit opt-in
Using Chrome in Incognito mode requires allowing third-party cookies. These can be found under Chrome > Settings… > Privacy and Security > Third-party cookies. Enable the Allow third-party cookies option.Safari 26.1 and older - Manual handshake
Older Safari versions require a multi-step handshake that prompts users to explicitly allow third-party cookies:- When the embedded dashboard loads, a
Cookies are not permittedmessage appears with a button to visit the Omni instance directly. - After visiting Omni in a non-embedded context, the user returns to the embedded page.
- Safari prompts the user to allow access to “use cookies and website data”. Clicking Allow displays the embedded dashboard.
Vanity domains - Alternative approach
Configuring a vanity domain allows Omni cookies to originate from your embedding domain, making them first-party cookies. This eliminates third-party cookie restrictions entirely across all browser versions. Vanity domains require infrastructure setup but provide a consistent experience regardless of browser version or privacy settings.Vanity domain embeds continue to use the Storage Access API handshake flow even on Safari 26.2+, as CHIPS partitioned cookies do not support custom domain attributes.
Per-user database OAuth
Per-user OAuth for database connections is only supported with vanity-domain embeds. When using per-user OAuth, Omni opens a popup for database authentication. This popup must share the same cookie partition as the embedded iframe to complete the OAuth flow. Default embed domains (embed-*) use a different registrable domain than your embedding page, which places them in separate cookie partitions and prevents the OAuth flow from completing.
Vanity domains solve this by using your own subdomain (e.g., omni.myapp.com embedded in myapp.com), keeping both the iframe and popup in the same cookie partition.
