Diagram
← Developer reference

How diagrams are sandboxed

Diagram HTML runs in a sandbox with an opaque origin, so a diagram's scripts can't read your session or act as you. What works and what doesn't inside a diagram.

Diagram treats every diagram's HTML as untrusted, including your own. It's never rendered as part of a Diagram page.

  • https://diagram.la/<id> shows the diagram in an <iframe> with the sandbox attribute.
  • The frame loads https://diagram.la/<id>/raw, which is sent with a Content-Security-Policy: sandbox header, so it stays sandboxed even when opened directly.
  • The sandbox gives the diagram an opaque origin. Its scripts can't read Diagram's cookies, can't call the API as the viewer, and can't reach the page around it.

What works inside a diagram

  • Inline <script> and <style>, and scripts, styles, fonts, and images loaded from other sites such as a CDN.
  • SVG, canvas, CSS animation, and click, hover, and zoom interactions.
  • Links that open in a new tab.

What doesn't

  • Forms. Submitting them is blocked.
  • Cookies, localStorage, sessionStorage, and IndexedDB. Scripts that touch them will throw, so wrap that code in try/catch.
  • Top-level navigation, and framing the diagram from other sites.
  • Files next to the HTML in your repo. Inline them or load them from a URL.

Accounts and keys

  • Sign-in is Google only. The session is an httpOnly cookie.
  • API keys are stored as SHA-256 hashes, shown once, and can be revoked on the API keys page. Each key acts as the account that created it.
  • Only a project's owner can see and change it, plus the emails the owner adds as members, who can only read. Nobody else, including Diagram's own staff accounts, can list or open a private diagram. A public diagram opens for anyone with its exact link.