Understanding Remote Embed Authorization

The Swiffle Grid admin lets you authorize a remote site’s URL — WordPress or not — to embed your articles and WooCommerce products in a read-only HTML block snippet. The Gutenberg and Elementor block builders let you create this snippet, which can then be embedded in the HTML of any remote page authorized in your Swiffle Grid admin’s allow-list.

The snippet is independent of the block that generated it: deleting or modifying that original block never affects the remote HTML, which keeps working exactly as it was set up. The data it displays (articles, products, etc.), however, is refreshed in real time.

What you’re actually authorizing

When you add a URL to your allow-list, you choose exactly which data sources that URL can query remotely — each with its own checkbox:

SourceWhat it exposes
ArticlesYour WordPress posts
WooCommerce productsYour store’s product catalog
XLSX filesAny spreadsheet source configured on a block
CSV filesComma- or semicolon-separated data sources
RSS feedsAny RSS source configured on a block
Custom connectorsYour own custom data connectors
No source checked means no access granted. Only once a source is explicitly authorized for a given URL can that URL actually pull data from it. This gives you precise, per-domain control over what’s genuinely shared — instead of an all-or-nothing choice: one URL might only ever see your articles, while another also has access to your products, without ever touching your CSV or XLSX files.
⚠️ Why this matters. The snippet itself is just plain HTML: nothing technically stops someone from editing it to request a different source than originally intended. It’s the checkboxes on your own site — not the snippet’s content — that determine what can actually be served.

Special case: a remote WordPress site

If the authorized remote site happens to be WordPress itself, its administrator can install the free version of Swiffle Grid and build a data block pointing at your site (by entering your URL in the „Site home URL” field). They can then generate, in turn, a snippet embeddable on yet another remote site — always within the limits of whatever sources you’ve authorized for their URL.

Why an editable „Site home URL” matters more than it looks

At first glance, this might not seem to add much over simply handing out a ready-made HTML snippet directly. In practice, it changes everything.

Say you run a job board and want to let partner sites showcase your listings. The straightforward approach — exporting one HTML snippet and distributing it to every partner — locks them all into the exact same card design, pagination, and settings. Nobody can adapt it to fit their own site.

Instead, you tell each partner: „Install the free Swiffle Grid plugin on a WordPress site, build a block, and set its Site home URL field to mine to pull my job listings.” Each partner then designs their own block — their own colors, layout, card style, pagination — fully adapted to their own site. Once they’re happy with it, they export the resulting HTML snippet and paste it wherever they actually want it live, including on a site that isn’t WordPress at all.

✅ The key advantage. Once that snippet is exported, the WordPress site used to design it is no longer needed. The partner can delete it entirely — the exported snippet keeps working on its own, still pulling live data from your site, still respecting whatever sources you authorized for that URL. The WordPress install, and the Site home URL field on it, were only ever a design tool — never a dependency.