Support in current browsers

Checked against the current browser versions recorded in MDN browser data 8.0.7.

BrowserMinimumOutcomeReason
Chrome150WorksEvery required mapped BCD feature is available without a recorded qualification.
Edge150WorksEvery required mapped BCD feature is available without a recorded qualification.
Firefox152WorksEvery required mapped BCD feature is available without a recorded qualification.
Safari26.5Not supportedAt least one required mapped feature is not available at this browser baseline.
Chrome for Android150WorksEvery required mapped BCD feature is available without a recorded qualification.
Firefox for Android152Not supportedAt least one required mapped feature is not available at this browser baseline.
Safari on iOS26.5Not supportedAt least one required mapped feature is not available at this browser baseline.
Android WebView150WorksEvery required mapped BCD feature is available without a recorded qualification.
Samsung Internet29.0WorksEvery required mapped BCD feature is available without a recorded qualification.

What this feature can and cannot do

Helps protect against

  • Credential-bearing cross-origin resource inclusion
  • Isolation deployment gaps

Does not guarantee

  • Public resource disclosure
  • Application authorisation
  • CORS correctness

What you need before using it

  • COEP deployment
  • A resource inventory that tolerates credential omission

Fallback to keep in place

Use require-corp with explicit CORS or CORP opt-in from embedded resources.