Troubleshooting Signed URL IFrame Embedding: Resolving "Access Denied – The Embed Dashboard Link Is Invalid or Expired" in Bold BI
Overview
This article explains how to troubleshoot the following error when embedding a Bold BI dashboard using Signed URL Authentication in an iframe:
This issue can occur even when the dashboard ID, Embed Secret, user information, and expiration timestamp are configured correctly.
Scenario
A user embeds Bold BI dashboards within a custom application using an iframe and wants to eliminate the dependency on:
- Browser cookies
- Separate Bold BI login sessions
- Cookie-based authentication
To achieve this, the user implements Signed URL Authentication for dashboard embedding. However, when accessing the dashboard through the generated embed URL, the following error is displayed:
Access Denied – The Embed Dashboard Link Is Invalid or Expired
Root Cause
The issue occurs when the generated HMAC SHA256 Base64 signature is URL-encoded using the JavaScript encodeURIComponent() method before it is appended to the embed URL.
Incorrect Implementation:
&embed_signature=${encodeURIComponent(signature)}
The encodeURIComponent() method modifies Base64 characters contained within the generated signature. For example:
+ becomes %2B
/ becomes %2F
= becomes %3D
As a result, the signature value received by Bold BI differs from the original signature that was generated using the Embed Secret.
Since Bold BI validates the exact signature generated from the embed parameters and Embed Secret, any modification to the signature causes the validation process to fail, resulting in the following error:
Access Denied – The Embed Dashboard Link Is Invalid or Expired
Solution
Do not URL-encode the generated signature.
Append the original HMAC SHA256 Base64 signature directly to the embed URL without modification.
Recommended Implementation
&embed_signature=${signature}
After applying the change, reload the embedded dashboard. The dashboard should load successfully if all embed parameters and the Embed Secret are valid.
NOTE: After the signature is generated:
- Do not modify embed secret key.
- Do not URL-encode the generated signature.
Any change to the signed URL after signature generation will invalidate the signature and cause authentication to fail.
Sample Flow
const embedParameters = parameters.join("&");
const signature = await hmacSha256Base64(
cfg.embedSecret,
embedParameters
);
return `${dashboardUrl}?${embedParameters}&embed_signature=${signature}`;
Additional References
- How to embed dashboard using SSO without login prompt
- How to embed dashboards in Bold BI using SSO
- Samples in Iframe Embedding
Conclusion
When using Signed URL Authentication, the generated HMAC SHA256 Base64 signature must be passed to Bold BI exactly as it was created. Applying encodeURIComponent() to the signature alters its value and causes signature validation to fail, resulting in the "Access Denied – The Embed Dashboard Link Is Invalid or Expired" error. Removing the URL encoding resolves the issue and allows the embedded dashboard to load successfully.