# blocks/embed

> Embed — allow-listed providers (YouTube, Vimeo, Loom, CodePen, Spotify) play in a sandboxed `<iframe>` that loads only when clicked, so nothing third-party is fetched until then.

Embed (F-36) — allow-listed providers (YouTube, Vimeo, Loom, CodePen, Spotify) play in a sandboxed `<iframe>` that loads only when clicked, so nothing third-party is fetched until then. Any other URL becomes a link card and never gets a frame. A host `unfurl(url) → Promise<{ title }>` option may title the cards (oEmbed / OpenGraph fetching belongs on your server). Pasting a provider link into an empty line embeds it.

```js
import embed from 'verbal-editor/blocks/embed';
```

| JS gzip | CSS gzip |
| --- | --- |
| 1.27 KB | 0.51 KB |

See it live on [Media](#/examples/media) — every example page on the landing is editable.

## Contract

|  |  |
| --- | --- |
| Block type | `embed` |
| Content | no text of its own |
| Props | `url: string` |
| Slash menu | `⧉ Embed` |
| Keywords | `video` `youtube` `link` `bookmark` |
| Copies as | `Markdown` `HTML` |

## Acceptance

| Feature | Acceptance | Budget |
| --- | --- | --- |
| F-36 · Embeds | Unknown providers never produce an unsandboxed frame | ≤ 2KB |
