PI Vision Web View+
A practical guide to embedding web pages and PI Vision displays in a PI Vision display with the right security, browser, and server configuration.
Before you configure anything
Know what the browser will allow
Web View+ uses an embedded frame to display another web page inside PI Vision. That means the page must be allowed to load in a frame by both the PI Vision server configuration and the target website’s response headers. A URL that opens normally in a browser can still be blocked when it is embedded.
PI Vision policy
The PI Vision web application must permit the frame source. This guide uses the FrameSrcPolicy setting in the PI Vision web.config file.
Target policy
The destination page must not deny framing through X-Frame-Options or Content-Security-Policy frame-ancestors.
Display workflow
Web View+ needs a valid URL and enough space on the display to make the embedded page useful and readable.
Only embed pages you trust. Framing a page gives it a place inside an operational display. Review the destination, authentication behavior, data exposure, and ownership before using it in production.
Step 1
Allow frames in the PI Vision web application
On the PI Vision server, locate the web application’s web.config file. The default installation path is:
C:\Program Files\PIPC\PIVision\web.config
Back up the file before editing it. In the appSettings section, add or update the frame policy setting used by your PI Vision deployment:
<add key="FrameSrcPolicy" value="Disable" />
After saving the configuration, follow your normal IIS change procedure. Depending on the deployment, the application pool or web application may reload automatically; verify the site in a controlled test before making the setting available to production users.

Step 2
Test whether the target page supports framing
Open the target URL directly first, then test it with a frame checker such as iFrame Tester. This helps separate a PI Vision configuration problem from a policy returned by the destination website.
Check the exact URL
Test the same protocol, hostname, path, and query parameters that you intend to use in Web View+. Redirects and authentication pages can behave differently from the final destination.
Inspect the response policy
Look for X-Frame-Options and Content-Security-Policy frame-ancestors. A restrictive policy can block framing even when the page works as a top-level browser tab.
Confirm ownership
If you own the destination, configure its response headers to allow the intended PI Vision origin. Use the narrowest trusted origin that supports the workflow.
Do not treat a permissive header as a security feature. Allow framing only for the origins and pages that need it, and review the implications with the owner of the target application.
Step 3
Add Web View+ to the PI Vision display
Once the server and target page are ready, open the PI Vision display and add Web View+ from Vision Library+. Enter the target URL in the symbol configuration and size the symbol so the embedded page has enough room to remain useful.
Keep the destination clear
Use a stable, documented URL and avoid embedding an unexpected login or redirect page. If the destination needs authentication, test the signed-in workflow with the intended users.
Keep the display readable
Reserve enough width and height for the embedded content. A frame that is technically working but too small to use is still a poor operational experience.
When the frame does not load
Troubleshoot by symptom
| Symptom | Likely area to check | First useful test |
|---|---|---|
| The symbol is blank | Invalid URL, target response, or frame policy | Open the exact URL directly and test it with an iFrame checker. |
| The browser reports that framing was denied | X-Frame-Options or CSP frame-ancestors on the destination | Inspect the response headers and ask the destination owner for the approved framing policy. |
| The page works directly but not in PI Vision | PI Vision FrameSrcPolicy, redirect, authentication, or origin mismatch | Check the PI Vision web.config setting and compare the final redirected URL with the tested URL. |
| The page loads but shows a login screen | Session, cookies, cross-origin authentication, or access rights | Test with the intended user account and document whether the target application supports embedded authentication. |
| The content is clipped | Symbol size, responsive layout, or nested scrolling | Resize the Web View+ symbol and check the target page at the display’s actual viewport size. |
Common questions
Web View+ embedding FAQ
Can every website be embedded in PI Vision? +
No. The destination website must permit framing, and its authentication and content security policies must work in the embedded context.
Where is the FrameSrcPolicy setting changed? +
It is changed in the PI Vision web application’s web.config file, commonly under C:\Program Files\PIPC\PIVision. Back up the file and follow your deployment’s IIS change procedure.
Should I use X-Frame-Options or CSP? +
The destination owner should use the policy supported by its application and browser compatibility requirements. Content-Security-Policy frame-ancestors provides a more flexible origin policy; do not add a permissive rule without reviewing the security impact.
Can Web View+ display another PI Vision display? +
It can be used for an approved PI Vision URL when the server, authentication, and frame policies allow the nested page. Test the exact URL with the intended user and deployment.
