Cross-Origin-Embedder-Policy

Response headers

Requires embedded cross-origin resources to opt in explicitly.

On the wireCross-Origin-Embedder-Policy: …
CategoryResponse headers

Headers the server attaches when it answers.

How to read this

  • The first digit of a status code carries the meaning: 4 means the request, 5 means the server.
  • 404 means "not there"; 403 means "there, but not for you". Swapping them makes debugging slower.
  • Header names are case-insensitive — Content-Type and content-type are the same header.
  • Caching and CORS problems usually come down to one header line, visible in the browser’s network tab.

Frequently asked questions

Q. What does HTTP Cross-Origin-Embedder-Policy mean?

Requires embedded cross-origin resources to opt in explicitly.

Q. What does Cross-Origin-Embedder-Policy look like on the wire?

It travels as Cross-Origin-Embedder-Policy: …

Q. Where does Cross-Origin-Embedder-Policy appear?

In response headers.

Q. What group does Cross-Origin-Embedder-Policy belong to?

The response headers group; the rest of that group is listed further down.

Same group

Reference docs