Cross-Origin-Resource-Policy (CORP) header

The HTTP Cross-Origin-Resource-Policy response header (CORP) indicates that the browser should block no-cors cross-origin or cross-site requests to the given resource.

It specifies resource owner's policy for what sites/origins should be allowed to load this resource.

Header type Response header

Syntax

http
Cross-Origin-Resource-Policy: same-site | same-origin | cross-origin

Directives

same-site

Resources can only be loaded from the same site.

same-origin

Resources can only be loaded from the same origin.

cross-origin

Resources can be loaded by any other origin/website.

Examples

For more examples, see https://resourcepolicy.fyi/.

Disallowing cross-origin no-cors requests

The Cross-Origin-Resource-Policy header below will cause compatible user agents to disallow cross-origin no-cors requests:

http
Cross-Origin-Resource-Policy: same-origin

Specifications

Specification
Fetch
# cross-origin-resource-policy-header

Browser compatibility

desktop mobile
Chrome
Edge
Firefox
Opera
Safari
Chrome Android
Firefox for Android
Opera Android
Safari on iOS
Samsung Internet
WebView Android
WebView on iOS
Cross-Origin-Resource-Policy
Chrome – Full support
Chrome 73 (Release date: 2019-03-12)
footnote
footnote Until version 75, downloads for files with this header would fail in Chrome. See bug 41452948.
footnote From version 80 to 85, linearized PDFs served inline with this header fail to render properly. See bug 40127935. From version 86, partial PDF loading is disabled.
Edge – Full support
Edge 79 (Release date: 2020-01-15)
footnote Full support
Firefox – Full support
Firefox 74 (Release date: 2020-03-10)
footnote Full support
Opera – Full support
Opera 60 (Release date: 2019-04-09)
footnote
footnote Until version 62, downloads for files with this header would fail in Opera. See bug 41452948.
footnote From version 67 to 85, linearized PDFs served inline with this header fail to render properly. See bug 40127935. From version 72, partial PDF loading is disabled.
Safari – Full support
Safari 12 (Release date: 2018-09-17)
footnote Full support
Chrome Android – Full support
Chrome Android 73 (Release date: 2019-03-12)
footnote
footnote Until version 75, downloads for files with this header would fail in Chrome Android. See bug 41452948.
footnote From version 80 to 85, linearized PDFs served inline with this header fail to render properly. See bug 40127935. From version 86, partial PDF loading is disabled.
Firefox for Android – Full support
Firefox for Android 79 (Release date: 2020-07-28)
footnote Full support
Opera Android – Full support
Opera Android 52 (Release date: 2019-05-17)
footnote
footnote Until version 54, downloads for files with this header would fail in Opera Android. See bug 41452948.
footnote From version 57 to 85, linearized PDFs served inline with this header fail to render properly. See bug 40127935. From version 61, partial PDF loading is disabled.
Safari on iOS – Full support
Safari on iOS 12 (Release date: 2018-09-17)
footnote Full support
Samsung Internet – Full support
Samsung Internet 11 (Release date: 2019-12-05)
footnote Full support
WebView Android – Full support
WebView Android 73 (Release date: 2019-03-12)
footnote
footnote Until version 75, downloads for files with this header would fail in WebView Android. See bug 41452948.
footnote From version 80 to 85, linearized PDFs served inline with this header fail to render properly. See bug 40127935. From version 86, partial PDF loading is disabled.
WebView on iOS – Full support
WebView on iOS 12 (Release date: 2018-09-17)
footnote Full support

Legend

Tip: you can click/tap on a cell for more information.

Full support
Full support
See implementation notes.

See also