Cross-Origin-Embedder-Policy-Report-Only (COEP) header

The HTTP Cross-Origin-Embedder-Policy-Report-Only (COEP) response header configures the current document's report-only policy for loading and embedding cross-origin resources that are requested in no-cors mode.

The header allows website administrators to report on resources that would be blocked by Cross-Origin-Embedder-Policy, without preventing them from being loaded. This allows for a softer rollout of enforcement.

Violations of the policy may be reported using the Reporting API. Reports can be observed in the page for which the policy is being set using a ReportingObserver, and sent to server endpoints defined in a Reporting-Endpoints HTTP response header, and selected using the report-to parameter. For more information see COEPViolationReport.

Header type Response header

Syntax

http
Cross-Origin-Embedder-Policy-Report-Only: <token>; <parameter>

Directives

The header should only be set with just one token and a report-to endpoint.

Setting the header more than once or with multiple tokens is equivalent to setting unsafe-none. Omitting report-to makes the header functionally inert.

The <token> value can be one of:

unsafe-none

Allows the document to load cross-origin resources requested in no-cors mode without giving explicit permission through the Cross-Origin-Resource-Policy header. This is the default value.

require-corp

A document can only load resources requested in no-cors mode from the same origin, or resources that have explicitly set the Cross-Origin-Resource-Policy header to a value that allows it to be embedded.

Cross-origin resource loading will be blocked by COEP unless:

  • The resource is requested in no-cors mode and the response includes a Cross-Origin-Resource-Policy header that allows it to be loaded into the document origin.
  • The resource is requested in cors mode; for example, in HTML using the crossorigin attribute, or in JavaScript by making a request with {mode="cors"}. Note that requests made in cors mode won't be blocked by COEP or trigger COEP violations, but must still be permitted by CORS.
credentialless

A document can load cross-origin resources that are requested in no-cors mode without an explicit permission via the Cross-Origin-Resource-Policy header. In this case requests are sent without credentials: cookies are omitted in the request, and ignored in the response.

The cross-origin loading behavior for other request modes is the same as for require-corp. For example, a cross-origin resource requested in cors mode must support (and be permitted by) CORS.

The <parameter> is optional, and can be one of:

report-to <endpoint_name> Optional

The <endpoint_name> is the name of the endpoint to which policy violations will be sent. The mapping between the name and a particular endpoint is defined separately in the Reporting-Endpoints HTTP header.

Specifications

Specification
HTML
# coep

Browser compatibility

desktop mobile
Chrome
Edge
Firefox
Opera
Safari
Chrome Android
Firefox for Android
Opera Android
Safari on iOS
Samsung Internet
WebView Android
WebView on iOS
Cross-Origin-Embedder-Policy
Chrome – Full support
Chrome 83 (Release date: 2020-05-19)
footnote Full support
Edge – Full support
Edge 83 (Release date: 2020-05-21)
footnote Full support
Firefox – Full support
Firefox 79 (Release date: 2020-07-28)
footnote Full support
Opera – Full support
Opera 69 (Release date: 2020-06-24)
footnote Full support
Safari – Full support
Safari 15.2 (Release date: 2021-12-13)
footnote Full support
Chrome Android – Full support
Chrome Android 83 (Release date: 2020-05-19)
footnote Full support
Firefox for Android – Full support
Firefox for Android 79 (Release date: 2020-07-28)
footnote Full support
Opera Android – Full support
Opera Android 59 (Release date: 2020-06-30)
footnote Full support
Safari on iOS – Full support
Safari on iOS 15.2 (Release date: 2021-12-13)
footnote Full support
Samsung Internet – Full support
Samsung Internet 13 (Release date: 2020-12-02)
footnote Full support
WebView Android – Full support
WebView Android 86 (Release date: 2020-10-20)
footnote Full support
WebView on iOS – Full support
WebView on iOS 15.2 (Release date: 2021-12-13)
footnote Full support
credentialless
Chrome – Full support
Chrome 96 (Release date: 2021-11-15)
footnote Full support
Edge – Full support
Edge 96 (Release date: 2021-11-19)
footnote Full support
Firefox – Full support
Firefox 119 (Release date: 2023-10-24)
footnote Full support
Opera – Full support
Opera 82 (Release date: 2021-12-02)
footnote Full support
Safari – No support
Safari
footnote No support
Chrome Android – Full support
Chrome Android 96 (Release date: 2021-11-15)
footnote Full support
Firefox for Android – No support
Firefox for Android
footnote No support
Opera Android – No support
Opera Android
footnote No support
Safari on iOS – No support
Safari on iOS
footnote No support
Samsung Internet – Full support
Samsung Internet 17 (Release date: 2022-05-04)
footnote Full support
WebView Android – Full support
WebView Android 96 (Release date: 2021-11-15)
footnote Full support
WebView on iOS – No support
WebView on iOS
footnote No support
report-to parameter
Chrome – Full support
Chrome 96 (Release date: 2021-11-15)
footnote Full support
Edge – Full support
Edge 96 (Release date: 2021-11-19)
footnote Full support
Firefox – No support
Firefox
footnote
footnote See bug 1652926
Opera – Full support
Opera 82 (Release date: 2021-12-02)
footnote Full support
Safari – No support
Safari
footnote No support
Chrome Android – Full support
Chrome Android 96 (Release date: 2021-11-15)
footnote Full support
Firefox for Android – No support
Firefox for Android
footnote No support
Opera Android – No support
Opera Android
footnote No support
Safari on iOS – No support
Safari on iOS
footnote No support
Samsung Internet – Full support
Samsung Internet 17 (Release date: 2022-05-04)
footnote Full support
WebView Android – Full support
WebView Android 96 (Release date: 2021-11-15)
footnote Full support
WebView on iOS – No support
WebView on iOS
footnote No support

Legend

Tip: you can click/tap on a cell for more information.

Full support
Full support
No support
No support
See implementation notes.

See also