Meta tags:
description= The oEmbed spec;
Headings (most frequently used words):
response, the, type, example, video, link, oembed, table, of, contents, quick, full, spec, security, considerations, discovery, more, examples, authors, implementations, configuration, consumer, request, provider, providers, consumers, libraries, press, and, links, json, xml, parameters, photo, rich, errors,
Text of the page (most frequently used words):
the (143), oembed (61), com (56), http (42), url (42), type (30), this (28), and (28), format (26), for (26), https (25), flickr (25), must (24), xml (22), resource (22), json (21), #response (21), html (21), provider (19), providers (19), required (19), parameters (18), github (17), are (17), www (17), consumer (16), link (15), may (15), optional (14), api (13), request (13), should (13), specified (13), photos (13), width (12), height (12), endpoint (12), services (11), parameter (11), not (11), consumers (10), example (10), value (10), scheme (10), version (9), title (9), responses (9), any (9), with (9), display (8), return (8), all (7), video (7), youtube (7), text (7), when (7), following (7), photo (7), present (7), below (7), embedded (7), spec (6), embed (6), iamcal (6), author_name (6), param (6), name (6), urls (6), that (6), domain (6), they (6), valid (6), used (6), maxheight (6), maxwidth (6), pixels (6), python (5), some (5), use (5), utf (5), author_url (5), provider_name (5), provider_url (5), application (5), support (5), have (5), representation (5), defined (5), thumbnail (5), types (5), pairs (5), bees (5), elixir (4), php (4), also (4), information (4), encoding (4), more (4), examples (4), contain (4), either (4), within (4), 2fflickr (4), 2fphotos (4), 2fbees (4), 2f2362225867 (4), rel (4), alternate (4), bacon (4), lollys (4), profile (4), element (4), can (4), choose (4), their (4), xss (4), one (4), provide (4), requested (4), data (4), such (4), image (4), only (4), key (4), each (4), returned (4), foo (4), which (4), wildcards (4), document (3), leah (3), iframely (3), java (3), web (3), there (3), rather (3), than (3), discovery (3), cal (3), standalone (3), yes (3), cache_age (3), 425 (3), 344 (3), full (3), other (3), href (3), from (3), avoid (3), iframe (3), specify (3), without (3), embedding (3), sent (3), has (3), allows (3), then (3), error (3), codes (3), part (3), obey (3), content (3), allow (3), representing (3), into (3), ignore (3), thumbnail_width (3), thumbnail_url (3), thumbnail_height (3), baz (3), mime (3), query (3), arguments (3), configuration (3), stored (2), please (2), fork (2), mailing (2), list (2), node (2), aws (2), serverless (2), furlex (2), jquery (2), micawber (2), pyembed (2), pyoembed (2), oembed_links (2), org (2), embera (2), essence (2), services_oembed (2), microlink (2), embeds (2), wordpress (2), registry (2), encouraged (2), add (2), implementations (2), culver (2), gmail (2), henderson (2), authors (2), zackscott (2), user (2), object (2), m3r2xdcem6a (2), allowfullscreen (2), true (2), allowscriptaccess (2), always (2), attribute (2), needed (2), header (2), elements (2), displays (2), attacks (2), cannot (2), access (2), will (2), security (2), considerations (2), directly (2), instead (2), doesn (2), status (2), padding (2), margins (2), wish (2), load (2), off (2), vulnerabilities (2), rich (2), wishes (2), player (2), videos (2), static (2), author (2), owner (2), values (2), along (2), specific (2), described (2), associated (2), encoded (2), bar (2), specifying (2), body (2), well (2), formed (2), instance (2), 2362225867 (2), maximum (2), applies (2), supported (2), respected (2), requests (2), implements (2), portion (2), simple (2), describes (2), third (2), party (2), website (2), quick (2), check, contribute, ajaxian, blog, webmonkey, tutorial, official, press, links, microlinkhq, samples, sample, claytongentry, gateway, itteco, wrapper, starfishmod, michael, simons, django, coleifer, abarmat, rafaelmartins, ruby, netshade, perl, metacpan, release, mpratt, felixgirault, pear, net, package, libraries, viewer, tools, specifically, built, around, managing, many, consume, including, slack, currently, mechanism, strongly, 366, new, modify, yml, repo, available, programatically, file, richard, crowley, rcrowley, mike, malone, mjmalone, 86400, linklog, 1206113631, amazing, nintendo, facts, movie, src, shockwave, flash, watch, 3fv, 3dm3r2xdcem6a, contained, angle, brackets, plus, included, uri, reference, make, discoverable, adding, head, existing, documents, setting, headers, vector, recommended, hosted, another, ensures, cookies, probably, want, filter, although, free, filtering, style, could, javascript, mailto, contains, private, non, public, extra, rely, control, 401, unauthorized, includes, however, both, 501, implemented, broad, determine, call, time, 404, found, conditions, specification, errors, markup, xhtml, basic, does, fall, under, categories, generic, providing, using, original, just, embeddable, playable, source, able, insert, img, optionally, include, long, same, these, understand, respect, cache, lifetime, seconds, suggested, describing, number, awesome, escaped, pcdata, root, called, child, containing, specifies, way, comprise, case, ignored, publishes, pair, clearly, state, whether, implicit, needs, passed, argument, note, itself, string, 300, 400, expect, welcome, custom, additional, else, see, retrieve, get, urlencoded, per, rfc, 1738, point, asterisk, path, subdomains, two, very, provided, service, where, representations, those, exchange, occurs, between, show, own, site, fetch, broken, three, parts, turn, page, structured, 240, 160, zb8t0193, farm4, 3123, 2341623661_7c99f48bbf_m, jpg, responds, 2341623661, makes, table, contents, allowing, sites, posts, having, parse,
Text of the page (random words):
oembed oembed oembed is a format for allowing an embedded representation of a url on third party sites the simple api allows a website to display embedded content such as photos or videos when a user posts a link to that resource without having to parse the resource directly this document is stored on github table of contents quick example full spec security considerations discovery more examples authors implementations 1 quick example a consumer e g wordpress makes the following http request http www flickr com services oembed format json url http 3a www flickr com photos bees 2341623661 the provider e g flickr then responds with an oembed response version 1 0 type photo width 240 height 160 title zb8t0193 url http farm4 static flickr com 3123 2341623661_7c99f48bbf_m jpg author_name bees author_url http www flickr com photos bees provider_name flickr provider_url http www flickr com this allows the consumer to turn a url to a flickr photo page into structured data to allow embedding of that photo in the consumer s website 2 full spec this spec is broken into three parts configuration the consumer request and the provider response an oembed exchange occurs between a consumer and a provider a consumer wishes to show an embedded representation of a third party resource on their own web site such as a photo or an embedded video a provider implements the oembed api to allow consumers to fetch that representation 2 1 configuration configuration for oembed is very simple providers must specify one or more url scheme and api endpoint pairs the url scheme describes which urls provided by the service may have an embedded representation the api endpoint describes where the consumer may request representations for those urls for instance url scheme http www flickr com photos api endpoint http www flickr com services oembed the url scheme may contain one or more wildcards specified with an asterisk wildcards may be present in the domain portion of the url or in the path within the domain portion wildcards may only be used for subdomains wildcards may not be used in the scheme to support http and https provide two url endpoint pairs some examples http www flickr com photos ok http www flickr com photos foo ok http flickr com photos ok http com photos not ok www flickr com photos not ok the api endpoint must point to a url with either http or https scheme which implements the api described below 2 2 consumer request requests sent to the api endpoint must be http get requests with all arguments sent as query parameters all arguments must be urlencoded as per rfc 1738 the following query parameters are defined as part of the spec url required the url to retrieve embedding information for maxwidth optional the maximum width of the embedded resource only applies to some resource types as specified below for supported resource types this parameter must be respected by providers maxheight optional the maximum height of the embedded resource only applies to some resource types as specified below for supported resource types this parameter must be respected by providers format optional the required response format when not specified the provider can return any valid response format when specified the provider must return data in the request format else return an error see below for error codes providers should ignore all other arguments it doesn t expect providers are welcome to support custom additional parameters some examples http flickr com services oembed url http 3a flickr com photos bees 2362225867 http flickr com services oembed url http 3a flickr com photos bees 2362225867 maxwidth 300 maxheight 400 format json note providers may choose to have the format specified as part of the endpoint url itself rather than as a query string parameter for instance url scheme http www flickr com photos api xml endpoint http www flickr com services oembed xml api json endpoint http www flickr com services oembed json in this case the format parameter is not needed and will be ignored when a provider publishes a url scheme and api endpoint pair they should clearly state whether the format is implicit in the endpoint or if it needs to be passed as an argument 2 3 provider response the response returned by the provider can be in either json or xml each format specifies a way of encoding name value pairs which comprise the response data each format has an associated mime type which must be returned in the content type header along with the response 2 3 1 json response json responses must contain well formed json and must use the mime type of application json the json response format may be requested by the consumer by specifying a format of json for example foo bar baz 1 the key value pairs to be returned are specified below all text must be utf 8 encoded 2 3 2 xml response xml responses must use the mime type of text xml the xml response format may be requested by the consumer by specifying a format of xml the response body must contain well formed xml with a root element called oembed and child elements for each key containing the value within the element body for example xml version 1 0 encoding utf 8 standalone yes oembed foo bar foo baz 1 baz oembed the key value pairs to be returned are specified below all text must be utf 8 encoded values should be escaped pcdata for example xml version 1 0 encoding utf 8 standalone yes oembed html b awesome b html oembed 2 3 4 response parameters responses can specify a resource type such as photo or video each type has specific parameters associated with it the following response parameters are valid for all response types type required the resource type valid values along with value specific parameters are described below version required the oembed version number this must be 1 0 title optional a text title describing the resource author_name optional the name of the author owner of the resource author_url optional a url for the author owner of the resource provider_name optional the name of the resource provider provider_url optional the url of the resource provider cache_age optional the suggested cache lifetime for this resource in seconds consumers may choose to use this value or not thumbnail_url optional a url to a thumbnail image representing the resource the thumbnail must respect any maxwidth and maxheight parameters if this parameter is present thumbnail_width and thumbnail_height must also be present thumbnail_width optional the width of the optional thumbnail if this parameter is present thumbnail_url and thumbnail_height must also be present thumbnail_height optional the height of the optional thumbnail if this parameter is present thumbnail_url and thumbnail_width must also be present providers may optionally include any parameters not specified in this document so long as they use the same key value format and consumers may choose to ignore these consumers must ignore parameters they do not understand 2 3 4 1 the photo type this type is used for representing static photos the following parameters are defined url required the source url of the image consumers should be able to insert this url into an img element only http and https urls are valid width required the width in pixels of the image specified in the url parameter height required the height in pixels of the image specified in the url parameter responses of this type must obey the maxwidth and maxheight request parameters 2 3 4 2 the video type this type is used for representing playable videos the following parameters are defined html required the html required to embed a video player the html should have no padding or margins consumers may wish to load the html in an off domain iframe to avoid xss vulnerabilities width required the width in pixels required to display the html height required the height in pixels required to display the html responses of this type must obey the maxwidth and maxheight request parameters if a provider wishes the consumer to just provide a thumbnail rather than an embeddable player they should instead return a photo response type 2 3 4 3 the link type responses of this type allow a provider to return any generic embed data such as title and author_name without providing either the url or html parameters the consumer may then link to the resource using the url specified in the original request 2 3 4 4 the rich type this type is used for rich html content that does not fall under one of the other categories the following parameters are defined html required the html required to display the resource the html should have no padding or margins consumers may wish to load the html in an off domain iframe to avoid xss vulnerabilities the markup should be valid xhtml 1 0 basic width required the width in pixels required to display the html height required the height in pixels required to display the html responses of this type must obey the maxwidth and maxheight request parameters 2 3 5 errors providers should return any error conditions as http status codes the following status codes are defined as part of the oembed specification 404 not found the provider has no response for the requested url parameter this allows providers to be broad in their url scheme and then determine at call time if they have a representation to return 501 not implemented the provider cannot return a response in the requested format this should be sent when for example the request includes format xml and the provider doesn t support xml responses however providers are encouraged to support both json and xml 401 unauthorized the specified url contains a private non public resource the consumer should provide a link directly to the resource instead of embedding any extra information and rely on the provider to provide access control 3 security considerations when a consumer displays any urls they will probably want to filter the url scheme to be one of http https or mailto although providers are free to specify any valid url without filtering javascript style urls could be used for xss attacks when a consumer displays html as with video embeds there s a vector for xss attacks from the provider to avoid this it is recommended that consumers display the html in an iframe hosted from another domain this ensures that the html cannot access cookies from the consumer domain 4 discovery oembed providers can choose to make their oembed support discoverable by adding link elements to the head of their existing x html documents or by setting link headers element example link rel alternate type application json oembed href http flickr com services oembed url http 3a 2f 2fflickr com 2fphotos 2fbees 2f2362225867 2f format json title bacon lollys oembed profile link rel alternate type text xml oembed href http flickr com services oembed url http 3a 2f 2fflickr com 2fphotos 2fbees 2f2362225867 2f format xml title bacon lollys oembed profile header example link http flickr com services oembed url http 3a 2f 2fflickr com 2fphotos 2fbees 2f2362225867 2f format json rel alternate type application json oembed title bacon lollys oembed profile link http flickr com services oembed url http 3a 2f 2fflickr com 2fphotos 2fbees 2f2362225867 2f format xml rel alternate type text xml oembed title bacon lollys oembed profile the urls contained within the href attribute or uri reference within angle brackets should be the full oembed endpoint plus url and any needed format parameter no other request parameters should be included in this url the type attribute must contain either application json oembed for json responses or text xml oembed for xml 5 more examples 5 1 video example request https www youtube com oembed url https 3a youtube com watch 3fv 3dm3r2xdcem6a format json response version 1 0 type video provider_name youtube provider_url https youtube com width 425 height 344 title amazing nintendo facts author_name zackscott author_url https www youtube com user zackscott html object width 425 height 344 param name movie value https www youtube com v m3r2xdcem6a fs 1 param param name allowfullscreen value true param param name allowscriptaccess value always param embed src https www youtube com v m3r2xdcem6a fs 1 type application x shockwave flash width 425 height 344 allowscriptaccess always allowfullscreen true embed object 5 2 link example request http iamcal com oembed url http 3a www iamcal com linklog 1206113631 format xml response xml version 1 0 encoding utf 8 standalone yes oembed version 1 0 version type link type author_name cal henderson author_name author_url http iamcal com author_url cache_age 86400 cache_age provider_name iamcal com provider_name provider_url http iamcal com provider_url oembed 6 authors cal henderson cal at iamcal com mike malone mjmalone at gmail com leah culver leah culver at gmail com richard crowley r at rcrowley org 7 implementations 7 1 providers providers are available programatically as a json file https oembed com providers json to add new providers please fork this repo on github and add modify providers yml there are currently 366 providers in the registry providers and consumers are strongly encouraged to use the discovery mechanism rather than the registry 7 2 consumers many services consume oembed information to display link information including wordpress and slack there are also some tools specifically built around managing url embeds iframely http iframely com oembed link viewer https oembed link microlink embed https microlink io embed 7 3 libraries php services_oembed http pear php net package services_oembed php essence https github com felixgirault essence php embera https github com mpratt embera perl web oembed https metacpan org release web oembed ruby oembed_links http github com netshade oembed_links python pyoembed http github com rafaelmartins pyoembed python pyembed http pyembed github io python python oembed https github com abarmat python oembed django micawber https github com coleifer micawber java java oembed https github com michael simons java oembed jquery oembed api wrapper https github com starfishmod jquery oembed all node js oembed api gateway https github com itteco iframely elixir furlex https github com claytongentry furlex elixir elixir oembed https github com r8 elixir oembed aws serverless oembed provider https github com aws samples sample serverless oembed node js oembed spec https github com microlinkhq oembed spec press and links the official oembed mailing list webmonkey tutorial leah s blog ajaxian this document is stored on github please check the mailing list fork and contribute
|