Content-Security-Policy: prefetch-src directive

Deprecated: This feature is no longer recommended. Though some browsers might still support it, it may have already been removed from the relevant web standards, may be in the process of being dropped, or may only be kept for compatibility purposes. Avoid using it, and update existing code if possible; see the compatibility table at the bottom of this page to guide your decision. Be aware that this feature may cease to work at any time.

Non-standard: This feature is not standardized. We do not recommend using non-standard features in production, as they have limited browser support, and may change or be removed. However, they can be a suitable alternative in specific cases where no standard option exists.

The HTTP Content-Security-Policy (CSP) prefetch-src directive specifies valid resources that may be prefetched or prerendered.

CSP version 3
Directive type Fetch directive
default-src fallback Yes. If this directive is absent, the user agent will look for the default-src directive.

Syntax

http
Content-Security-Policy: prefetch-src 'none';
Content-Security-Policy: prefetch-src <source-expression-list>;

This directive may have one of the following values:

'none'

No resources of this type may be loaded. The single quotes are mandatory.

<source-expression-list>

A space-separated list of source expression values. Resources of this type may be loaded if they match any of the given source expressions. For this directive, the following source expression values are applicable:

Example

Prefetch resources do not match header

Given a page with the following Content Security Policy:

http
Content-Security-Policy: prefetch-src https://example.com/

Fetches for the following code will return network errors, as the URLs provided do not match prefetch-src's source list:

html
<link rel="prefetch" href="https://example.org/" />
<link rel="prerender" href="https://example.org/" />

Specifications

This feature does not appear to be defined in any specification.

Browser compatibility

desktop mobile
Chrome
Edge
Firefox
Opera
Safari
Chrome Android
Firefox for Android
Opera Android
Safari on iOS
Samsung Internet
WebView Android
WebView on iOS
prefetch-src
Deprecated Non-standard
Chrome – No support
Chrome
footnote
footnote See bug 40090173
Edge – No support
Edge
footnote
footnote See bug 40090173
Firefox – No support
Firefox
footnote
footnote See bug 1457204
Opera – No support
Opera
footnote
footnote See bug 40090173
Safari – Full support
Safari 16.3 (Release date: 2023-01-23)
footnote
footnote See bug 185070
Chrome Android – No support
Chrome Android
footnote
footnote See bug 40090173
Firefox for Android – No support
Firefox for Android
footnote
footnote See bug 1457204
Opera Android – No support
Opera Android
footnote
footnote See bug 40090173
Safari on iOS – Full support
Safari on iOS 16.3 (Release date: 2023-01-23)
footnote
footnote See bug 185070
Samsung Internet – No support
Samsung Internet
footnote
footnote See bug 40090173
WebView Android – No support
WebView Android
footnote
footnote See bug 40090173
WebView on iOS – Full support
WebView on iOS 16.3 (Release date: 2023-01-23)
footnote
footnote See bug 185070

Legend

Tip: you can click/tap on a cell for more information.

Full support
Full support
No support
No support
Non-standard. Check cross-browser support before using.
Deprecated. Not for use in new websites.
See implementation notes.

See also