
4f1gn (4f1gn) asked a question.
We need to intergate 2 app both using Okta open id connect. Need is to embed app2 in app1 and use SSO if user has already signed in to app1 . We are running into issue and app2 is not getting rendered because Okta sets the header X-Frame-Options: SAMEORIGIN. Please suggest a secure way of authenticating in iframe

Thank you for contacting Okta :
X-Frame-Options is controlled by the iFrame Embedding feature flag which when enabled by the customer in their Admin Console, removes the X-Frame-Options: SAMEORIGIN header.
See https://help.okta.com/en/prod/Content/Topics/Settings/Settings_Customization.htm - Allow iFrame embedding
This error has the following solution in the following link : https://support.okta.com/help/s/article/Okta-in-IFrame-is-not-working
From the following link we have this solution :
Have a nice day,
Marius Gheorghe
Technical Support Engineer