Cross‑Origin Opener Policy (COOP)

Response header that isolates a browsing context from cross‑origin windows, mitigating cross‑origin side‑channel risks.

#web#security#headers

Last updated: 2025-09-07T00:00:00.000Z

Evidence

OTHER HTML Standard — Cross‑Origin Opener Policy Normative evidence

More context

COOP enforces process isolation for top‑level documents using values like same‑origin to reduce interference.