Embed component

Role: Site Administrator

An overview of the whitelist for third-party applications you can add to your site using the Embed component. Once an application is enabled for a site, anyone with an editing role can add content using the Embed component.

Related information

Whitelisted applications

Compliance

Whitelisted applications released by the Fresco team have a valid TPSA and have been assessed by the InfoSec team.

Embedding a whitelisted service assumes compliance with the following:

  • The embed is display-only/public-content only
  • No API keys, secrets, tokens, or service credentials are exposed to site visitors
  • No University SSO, staff/student identifiers, email addresses, or personal data are passed to the embed provider unless separately assessed
  • No confidential, sensitive, unpublished, participant-level, or restricted research data is embedded
  • The service is not used to collect form submissions, comments, analytics identifiers, or user-generated content unless separately reviewed
  • Site Owners remain accountable for ensuring the content they embed is appropriate for publication and licensing

Available embeddable services

  • Figshare Web Gallery and Figshare iFrame
  • Google Maps
  • MazeMaps (Oxford Maps)
  • Panopto hosted videos
  • Shiny/IDN
  • Audio:
    • PodOxford, Apple Podcasts, Transistor.fm, Spotify and Acast
  • Collaboration:
    • Miro collaborative whiteboard embeds
    • AirTable
  • Timeline.js interactive timeline embeds
  • Service Status Reporting Tool 
  • Social Media:
    • Facebook, Instagram and X
  • Microsoft Forms
    • Embeds have been approved on the basis that a form will be used only for brief general enquiries or simple feedback, and not for use-cases that require the collection of additional personal data
    • For example, a name and contact method (for the purpose of replying) can be collected, but no special category personal data can be collected. When embedding a form, editors must include details of this in their site's privacy policy describing how the data is collected and processed to be GDPR compliant. Fresco sites are provisioned with an unpublished Privacy Policy which can be edited and linked to in the Footer
  • Oxford Events
  • ThingLink
  • Matterport

Sharepoint Online is no longer supportable and is being removed from the whitelist.

Embed functionality is under development. This page will be updated as more applications are released. 

An indicative timeline is provided on the Fresco roadmap.

How to embed

  • Copy the embed code provided by the third-party application
  • Add the Embed component to a section level layout
  • Paste in the embed code

Please note the Fresco Service team can't troubleshoot issues with third-party applications. Refer to the support pages on the provider's website for guidance.

Why link to PDF's instead of embedding them?

In most cases, it's better to link to a PDF rather than embed it within a web page. Embedded PDFs are usually displayed in a limited viewing area, making them harder to read and navigate, particularly on smaller screens. This can create additional barriers for some users.

Opening a PDF in its own browser tab or window provides a more comfortable and consistent reading experience, making it easier to read, search, zoom and download the document as needed.

Changes may have been made to enhance this feature since we last updated this page. See What’s new for the latest release information.

Last updated: 7 September 2026