# Embedding Kibana in Company Portal – CORS and Iframe Customization on Elastic Cloud

**URL:** <https://discuss.elastic.co/t/embedding-kibana-in-company-portal-cors-and-iframe-customization-on-elastic-cloud/380549>\
**Category:** Kibana\
**Tags:** kibana-plugin-development, dashboard\
**Created:** [July 29, 2025, 4:18pm UTC](https://discuss.elastic.co/t/embedding-kibana-in-company-portal-cors-and-iframe-customization-on-elastic-cloud/380549 "2025-07-29T16:18:22Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![lithindj](https://avatars.discourse-cdn.com/v4/letter/l/58f4c7/32.png) [@lithindj](https://discuss.elastic.co/u/lithindj)\
**Post date:** [July 29, 2025, 4:18pm UTC](https://discuss.elastic.co/t/embedding-kibana-in-company-portal-cors-and-iframe-customization-on-elastic-cloud/380549/1 "2025-07-29T16:18:22Z")

</div>

We’re currently working on embedding Kibana dashboards (hosted on Elastic Cloud) into our internal company portal via an iframe, and we’re running into a couple of key challenges:  
CORS issues:  
Kibana and our portal are hosted on different domains, and browser **CORS** policies are blocking XHR/fetch calls within the embedded iframe. I’ve seen discussions about updating the `kibana.yml` file, but I believe we don't have that flexibility since we're using **Elastic Cloud**.

Is there any way to configure settings like `xpack.security.sameSiteCookies`, `basePath`, etc., in a **cloud-hosted Kibana environment**?

Iframe Styling Limitations:  
Due to the Same-Origin Policy, we’re unable to style or modify the Kibana iframe (e.g., apply branding or CSS changes).

- Are there any Elastic-supported options to customize the embedded Kibana UI?
- Is using a reverse proxy a viable solution in Elastic Cloud?

When testing locally, it seemed like we would need to reverse proxy **all requests Kibana makes** , which may be complex.

Any guidance on best practices for securely embedding Kibana with support for custom branding would be greatly appreciated.

---

<div class="post-metadata">

**Author:** ![nickpeihl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nickpeihl/32/112622_2.png) [@nickpeihl](https://discuss.elastic.co/u/nickpeihl)\
**Post date:** [July 29, 2025, 5:29pm UTC](https://discuss.elastic.co/t/embedding-kibana-in-company-portal-cors-and-iframe-customization-on-elastic-cloud/380549/2 "2025-07-29T17:29:13Z")

</div>

You can configure Kibana settings (such as `xpack.security.sameSiteCookies`) in Elastic Cloud Console. See [Edit Stack Settings](https://www.elastic.co/docs/deploy-manage/deploy/elastic-cloud/edit-stack-settings) for more info.

We also have a ["How to embed Kibana Dashboards"](https://www.elastic.co/blog/how-to-embed-kibana-dashboards) blog post that provides tips.

---

<div class="post-metadata">

**Author:** ![lithindj](https://avatars.discourse-cdn.com/v4/letter/l/58f4c7/32.png) [@lithindj](https://discuss.elastic.co/u/lithindj)\
**Post date:** [July 31, 2025, 11:16am UTC](https://discuss.elastic.co/t/embedding-kibana-in-company-portal-cors-and-iframe-customization-on-elastic-cloud/380549/3 "2025-07-31T11:16:50Z")

</div>

Thank you. Setting `xpack.security.sameSiteCookies: None` now allows iframe authentication  
Aware that relying on sameSiteCookies: None comes with security and browser compatibility issues. What’s the recommended approach for securely embedding Elastic Cloud Kibana dashboards in a production environment? Are SAML/OIDC SSO or API-key-based solutions preferred?
