Cross-Origin-Opener-Policy
Cross-Origin-Opener-Policy severs the link between your page and any cross-origin window that opened it or that it opens. Combined with COEP it enables cross-origin isolation, which protects against Spectre-type side-channel attacks and blocks cross-origin window tampering.
Why it matters
Isolates the browsing context to prevent Spectre-type side-channel attacks and cross-origin window manipulation.
How to add Cross-Origin-Opener-Policy
add_header Cross-Origin-Opener-Policy "same-origin" always;Recommended value
same-originAvoid
unsafe-none (default — no isolation)Frequently asked questions
What does same-origin do for COOP?
It ensures your document only shares a browsing-context group with same-origin documents, cutting off references from cross-origin openers/popups. This is required (with COEP) to use powerful APIs like SharedArrayBuffer.
Will COOP break OAuth popups or third-party windows?
It can, because it cuts window.opener links. If you rely on postMessage with cross-origin popups, test carefully and consider same-origin-allow-popups as a middle ground.
Other header guides
What the HSTS header does, how to configure max-age, includeSubDomains and preload, and how to add it in Nginx, Apache, and Cloudflare.
Why the X-Content-Type-Options: nosniff header matters, what MIME sniffing is, and how to set it in Nginx, Apache, and Cloudflare.
How X-Frame-Options prevents clickjacking, DENY vs SAMEORIGIN, why frame-ancestors supersedes it, and how to set it in Nginx, Apache, and Cloudflare.
The X-XSS-Protection header is a legacy filter that can introduce vulnerabilities. Learn why modern guidance is to set it to 0 and rely on CSP.
Is Cross-Origin-Opener-Policy set on your site?
Scan any URL free to check Cross-Origin-Opener-Policy and every other security header.
Scan Now - Free