Sign in
Version 5.13.0, 2015-03-25
Report a bug

HTTP Header Frame Options

Document type: Expired Internet-Draft (websec WG)
Document stream: IETF
Last updated: 2013-01-07 (latest revision 2012-07-06)
Intended RFC status: Unknown
Other versions: (expired, archived): plain text, pdf, html

IETF State: Parked WG Document
Document shepherd: No shepherd assigned

IESG State: Expired
Responsible AD: (None)
Send notices to: No addresses provided

This Internet-Draft is no longer active. A copy of the expired Internet-Draft can be found here:


To improve the protection of web applications against Clickjacking this standards defines a http response header that declares a policy communicated from a host to the client browser whether the transmitted content MUST NOT be displayed in frames of other pages from different origins which are allowed to frame the content.


David Ross
Tobias Gondrom <>

(Note: The e-mail addresses provided for the authors of this Internet-Draft may no longer be valid)