Cross-Origin-Opener-Policy

Cross-Origin-Opener-Policy severs the link between your page and any cross-origin window that opened it or that it opens. Combined with COEP it enables cross-origin isolation, which protects against Spectre-type side-channel attacks and blocks cross-origin window tampering.

Why it matters

Isolates the browsing context to prevent Spectre-type side-channel attacks and cross-origin window manipulation.

How to add Cross-Origin-Opener-Policy

add_header Cross-Origin-Opener-Policy "same-origin" always;

Recommended value

same-origin

Avoid

unsafe-none  (default — no isolation)

Frequently asked questions

What does same-origin do for COOP?

It ensures your document only shares a browsing-context group with same-origin documents, cutting off references from cross-origin openers/popups. This is required (with COEP) to use powerful APIs like SharedArrayBuffer.

Will COOP break OAuth popups or third-party windows?

It can, because it cuts window.opener links. If you rely on postMessage with cross-origin popups, test carefully and consider same-origin-allow-popups as a middle ground.

Is Cross-Origin-Opener-Policy set on your site?

Scan any URL free to check Cross-Origin-Opener-Policy and every other security header.

Scan Now - Free