PerformanceResourceTiming: secureConnectionStart property

Baseline Widely available

This feature is well established and works across many devices and browser versions. It’s been available across browsers since October 2018.

Note: This feature is available in Web Workers.

The secureConnectionStart read-only property returns a timestamp immediately before the browser starts the handshake process to secure the current connection. If a secure connection is not used, the property returns zero.

Value

The secureConnectionStart property can have the following values:

  • A DOMHighResTimeStamp indicating the time immediately before the browser starts the handshake process to secure the current connection if the resource is fetched over a secure connection.
  • 0 if no secure connection is used.
  • 0 if the resource was instantaneously retrieved from a cache.
  • 0 if the resource is a cross-origin request and no Timing-Allow-Origin HTTP response header is used.

Examples

Measuring TLS negotiation time

The secureConnectionStart and requestStart properties can be used to measure how long it takes for the TLS negotiation to happen.

js
const tls = entry.requestStart - entry.secureConnectionStart;

Example using a PerformanceObserver, which notifies of new resource performance entries as they are recorded in the browser's performance timeline. Use the buffered option to access entries from before the observer creation.

js
const observer = new PerformanceObserver((list) => {
  list.getEntries().forEach((entry) => {
    const tls = entry.requestStart - entry.secureConnectionStart;
    if (tls > 0) {
      console.log(`${entry.name}: TLS negotiation duration: ${tls}ms`);
    }
  });
});

observer.observe({ type: "resource", buffered: true });

Example using Performance.getEntriesByType(), which only shows resource performance entries present in the browser's performance timeline at the time you call this method:

js
const resources = performance.getEntriesByType("resource");
resources.forEach((entry) => {
  const tls = entry.requestStart - entry.secureConnectionStart;
  if (tls > 0) {
    console.log(`${entry.name}: TLS negotiation duration: ${tls}ms`);
  }
});

Cross-origin timing information

If the value of the secureConnectionStart property is 0, the resource is either not using a secure connection or it is a cross-origin request. To allow seeing cross-origin timing information, the Timing-Allow-Origin HTTP response header needs to be set.

For example, to allow https://developer.mozilla.org to see timing resources, the cross-origin resource should send:

http
Timing-Allow-Origin: https://developer.mozilla.org

Specifications

Specification
Resource Timing
# dom-performanceresourcetiming-secureconnectionstart

Browser compatibility

desktop mobile server
Chrome
Edge
Firefox
Opera
Safari
Chrome Android
Firefox for Android
Opera Android
Safari on iOS
Samsung Internet
WebView Android
WebView on iOS
Deno
Node.js
secureConnectionStart
Chrome – Full support
Chrome 43 (Release date: 2015-05-19)
footnote Full support
Edge – Full support
Edge 18 (Release date: 2018-10-02)
footnote Full support
Firefox – Full support
Firefox 35 (Release date: 2015-01-13)
footnote Full support
Opera – Full support
Opera 30 (Release date: 2015-06-09)
footnote Full support
Safari – Full support
Safari 11 (Release date: 2017-09-19)
footnote Full support
Chrome Android – Full support
Chrome Android 43 (Release date: 2015-05-27)
footnote Full support
Firefox for Android – Full support
Firefox for Android 35 (Release date: 2015-01-13)
footnote Full support
Opera Android – Full support
Opera Android 30 (Release date: 2015-06-10)
footnote Full support
Safari on iOS – Full support
Safari on iOS 11 (Release date: 2017-09-19)
footnote Full support
Samsung Internet – Full support
Samsung Internet 4 (Release date: 2016-03-11)
footnote Full support
WebView Android – Full support
WebView Android 43 (Release date: 2015-05-27)
footnote Full support
WebView on iOS – Full support
WebView on iOS 11 (Release date: 2017-09-19)
footnote Full support
Deno – No support
Deno
footnote No support
Node.js – No support
Node.js 16.17 – 16.17 (Release date: 2022-08-16)
footnote Removed in 17 and later
Node.js – Full support
Node.js 18.2 (Release date: 2022-05-17)
footnote Full support

Legend

Tip: you can click/tap on a cell for more information.

Full support
Full support
No support
No support
Has more compatibility info.

See also