> ## Documentation Index
> Fetch the complete documentation index at: https://developers.myhero.so/llms.txt
> Use this file to discover all available pages before exploring further.

# Render an HTML block

> Serves a stored HTML block as a page for a sandboxed iframe, from a URL issued by `GET /media/html/{htmlId}/render-url`.

The response's `Content-Security-Policy` sandboxes the page into an opaque origin, even when opened directly, and allows no network access beyond jsDelivr, cdnjs and unpkg.



## OpenAPI

````yaml get /media/html/{htmlId}/render
openapi: 3.1.0
info:
  title: HERO API
  version: current
  description: |-
    The HERO REST API.

    See https://developers.myhero.so for the rendered docs.
servers:
  - url: https://app.myhero.so
security: []
paths:
  /media/html/{htmlId}/render:
    get:
      tags:
        - Media
      summary: Render an HTML block
      description: >-
        Serves a stored HTML block as a page for a sandboxed iframe, from a URL
        issued by `GET /media/html/{htmlId}/render-url`.


        The response's `Content-Security-Policy` sandboxes the page into an
        opaque origin, even when opened directly, and allows no network access
        beyond jsDelivr, cdnjs and unpkg.
      operationId: renderHtml
      parameters:
        - schema:
            type: string
            minLength: 1
          required: true
          name: htmlId
          in: path
        - schema:
            type: string
            minLength: 1
          required: true
          name: token
          in: query
        - schema:
            type: string
            enum:
              - light
              - dark
          required: false
          name: scheme
          in: query
      responses:
        '200':
          description: The widget page
          content:
            text/html:
              schema:
                type: string
        '403':
          description: Missing, invalid or expired token
          content:
            application/json:
              schema:
                type: object
                properties:
                  error:
                    type: string
                    description: |-
                      Error class name (e.g.

                      ValidationError, NotFound)
                  message:
                    type: string
                    description: Human-readable error message
                  details:
                    type: array
                    items: {}
                required:
                  - error
                  - message
        '404':
          description: Not found
          content:
            application/json:
              schema:
                type: object
                properties:
                  error:
                    type: string
                    description: |-
                      Error class name (e.g.

                      ValidationError, NotFound)
                  message:
                    type: string
                    description: Human-readable error message
                  details:
                    type: array
                    items: {}
                required:
                  - error
                  - message

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.