Every provider Calucon Third-Party Embed Gate recognises — 36 of them, all demonstrated below, 30 of them wired to live content. Nothing on this page contacts a third party until you press a button.
Check it yourself: developer tools → Network → tick “Disable cache” → reload, and sort by Domain. Nothing below has loaded; press one button and exactly one provider appears.
One honest caveat: the site sits behind Cloudflare, which injects its own analytics beacon (static.cloudflareinsights.com) into every page at the edge — after WordPress has finished, out of reach of any plugin, and not an embed. It is cookieless and it is disclosed in the privacy policy. Everything else in that list is calucon.de.
The providers
Open a group to see its embeds. Whose content is it? The provider’s own example where one exists, my own work where I have it, and museum or design-institution material otherwise — nobody’s personal post is here by accident.
One rule decided most of this page: nothing is embedded unless it is plainly the uploader’s to publish. That rules out more than it sounds like. The Dailymotion sample this page started with — inherited from the plugin’s own test fixtures — was a 45-minute television series re-uploaded by a stranger. Two providers below are empty for the same reason: Scribd and Imgur expose no uploader, so there is nothing to check.
Six are marked stand-in: the panel is real, the target is not, and there are three separate reasons. Google Forms and Calendly have no vendor demo, and a real one would send your answers into a stranger’s form or book time in their calendar. Instagram and Facebook point at Meta’s own documented example posts, both since deleted — kept, because a provider failing after consent is worth seeing. Scribd and Imgur are empty on the copyright rule above.
Video
YouTube
Pasted as youtube.com; loads back as youtube-nocookie.com. Measured: 6 cookies on the first, 0 on the second.
Vimeo
Loads back with dnt=1, which suppresses Vimeo’s analytics.
Dailymotion
VernissageTV’s tour of Making Africa at the Vitra Design Museum.
TED
VideoPress
An iframe and a companion script. One button releases both — the script waits in a hidden marker rather than growing a second panel.
TikTok
TikTok’s own documentation example. The blockquote and embed.js form TikTok also publishes rendered nothing here, with or without a gate in the way.
Audio and podcasts
Spotify
SoundCloud
Apple Music
Carries a sandbox attribute — preserved exactly when the embed is rebuilt, never widened.
Mixcloud
Pocket Casts
Social posts
Strava
Script-based, not an iframe: the loader is what gets held back. On a page with several activities one press loads them all, because Strava’s single script renders every placeholder at once.
X (Twitter)
just setting up my twttr
— jack (@jack) March 21, 2006
Bluesky
The quoted text is the provider’s own fallback, and it is still here with the script held back. Not every embed degrades this gracefully.
Bluesky is an open social network that gives creators independence from platforms, developers the freedom to build, and users a choice in their experience.
— Bluesky (@bsky.app)
Tumblr
Instagram stand-in target
The post in Meta’s own oEmbed documentation, which has since been deleted — so Instagram answers with “Page isn’t available”. Left as it is: the gate’s job ends at the request, and what a provider does with it afterwards is worth seeing too.
Facebook stand-in target
The post in Meta’s own embedded-posts documentation, by Facebook’s own page. It now answers 400. Meta’s two published examples are the only ones on this page that no longer exist.
An announcement from r/reddit, Reddit’s own account.
Documents and presentations
Scribd stand-in target
Scribd publishes uploads and names no uploader on the embed, so there is no way to tell from here whether a given document was its poster’s to post. Not worth guessing on someone else’s copyright.
Speaker Deck
Issuu
Wolfram Cloud
Amazon Kindle
Maps and 3D
Google Maps
OpenStreetMap
The privacy-friendlier alternative — still a third party, still gated.
Matterport
Sketchfab
The British Museum’s scan of the Rosetta Stone.
Forms, polls and scheduling
Crowdsignal
The same poll the plugin’s fixtures use, via poll.fm rather than the loader script. That script calls document.write, which only does anything while a document is still parsing — which is exactly what this URL gives it.
Google Calendar
Google Forms stand-in target
Typeform
One of Typeform’s own forms. Load it and it shows you a cookie banner of its own — a fair reminder that the gate stops the request, and what happens after you allow it is the provider’s business.
Calendly stand-in target
Images and everything else
Imgur stand-in target
Same reasoning as Scribd. Imgur albums carry no attribution in the embed, so provenance cannot be established without leaving the page.
GIPHY
Oskar Schlemmer’s Bauhaus logo, animated.
Kickstarter
The only descriptor that ships no kind, deliberately — it gets the generic panel. Recognised by name all the same.
Behaviour worth seeing
An unknown third party is gated too
The gate asks “is this host ours?”, not “do I recognise it?” — so something pasted in next year is covered without anyone editing a list.
Our own content is not gated
Same-origin iframes pass through byte-identical. This one loads immediately, with no button.
Where a provider ships both forms, the iframe is the safer paste
Many providers publish two snippets for the same content: an <iframe>, or a <blockquote> and a loader script. The gate releases either. In testing here, the script form of TikTok and Crowdsignal rendered nothing — but so did the same snippet on a page with no gate at all, which rules the gate out as the cause. Their iframe forms work, and that is what is demonstrated above; the gate recognises them by host either way. Where a provider offers both, the iframe has fewer moving parts and fails visibly rather than silently.
It works without JavaScript
Every panel carries a server-rendered link to the provider’s own site. Turn JavaScript off and the buttons stop working, but those links still go somewhere real.
Withdrawing consent
Consent memory is off here, so nothing is stored and every placeholder is active again next visit. This control is for sites that turn memory on.
Coverage
The named providers above get a recognisable label, an icon, a privacy-policy link and, where one exists, a privacy-preserving load target. The protection does not come from that list: any host that is not yours is held back, named or not. A provider nobody has heard of yet is covered without anyone editing anything.
Two providers load back somewhere different from where they were pasted: YouTube via www.youtube-nocookie.com, and Vimeo with dnt=1 merged into the query.
Detection detail
| Provider | Detected on | Kind | Method |
|---|---|---|---|
| YouTube | youtube.com, www.youtube.com, m.youtube.com, youtube-nocookie.com, www.youtube-nocookie.com, youtu.be | video | iframe |
| Vimeo | player.vimeo.com | video | iframe |
| Dailymotion | geo.dailymotion.com, www.dailymotion.com, dailymotion.com | video | iframe |
| TED | embed.ted.com, embed-ssl.ted.com | video | iframe |
| VideoPress | video.wordpress.com, videopress.com, v0.wordpress.com | video | iframe + script |
| TikTok | www.tiktok.com | video | iframe + script |
| Spotify | open.spotify.com | audio | iframe |
| SoundCloud | w.soundcloud.com | audio | iframe |
| Apple Music | embed.music.apple.com, embed.podcasts.apple.com | audio | iframe |
| Mixcloud | www.mixcloud.com, player-widget.mixcloud.com | audio | iframe |
| Pocket Casts | pca.st | audio | iframe |
| Strava | strava-embeds.com, www.strava-embeds.com | social | script |
| X (Twitter) | platform.twitter.com, platform.x.com | social | iframe + script |
| Bluesky | embed.bsky.app | social | iframe + script |
| Tumblr | embed.tumblr.com, assets.tumblr.com | social | iframe + script |
assets.pinterest.com | social | iframe + script | |
www.instagram.com, instagram.com, platform.instagram.com | social | iframe + script | |
www.facebook.com, web.facebook.com, connect.facebook.net | social | iframe + script | |
embed.reddit.com, www.redditmedia.com, embed.redditmedia.com | social | iframe + script | |
| Scribd | www.scribd.com, scribd.com | document | iframe + script |
| Speaker Deck | speakerdeck.com | document | iframe + script |
| Issuu | e.issuu.com | document | iframe |
| Wolfram Cloud | www.wolframcloud.com, wolframcloud.com | document | iframe + script |
| Amazon Kindle | read.amazon.com, read.amazon.co.uk, read.amazon.com.au, read.amazon.in, read.amazon.cn | document | iframe |
| Google Maps | www.google.com, google.com, maps.google.com | map | iframe |
| OpenStreetMap | www.openstreetmap.org, openstreetmap.org | map | iframe |
| Matterport | my.matterport.com | 3d | iframe |
| Sketchfab | sketchfab.com | 3d | iframe |
| Crowdsignal | poll.fm, secure.polldaddy.com, app.crowdsignal.com | form | iframe + script |
| Google Calendar | calendar.google.com | calendar | iframe |
| Google Forms | docs.google.com | form | iframe |
| Typeform | form.typeform.com, embed.typeform.com | form | iframe + script |
| Calendly | calendly.com, assets.calendly.com | calendar | iframe + script |
| Imgur | imgur.com, s.imgur.com | image | iframe + script |
| GIPHY | giphy.com | image | iframe + script |
| Kickstarter | www.kickstarter.com, kickstarter.com | generic | iframe |
Not a compliance claim: the plugin stops the requests, but it cannot know a site’s processing purposes. A privacy policy still has to name its providers.
