How to use this reference
Editorial guidance: model permission, document access and request eligibility separately. Review denial, revocation and navigation paths, minimize resource opt-in, and retain independent server authorization and CSRF defenses. Cookie availability does not establish authority for a business action.
Before reading
- Same-site versus same-origin relationships, embedded documents and HTTP cookies
Context and limits
- Both publications are Draft Community Group Reports. The API draft is outside W3C's standards track and is not a WHATWG Living Standard. The technical-standard taxonomy includes drafts; listed authors are the API's current editors.
- The companion Headers draft displays 17 December 2025. Its opt-in uses an existing grant; it does not create initial permission. Cookie attachment and CORS response readability remain separate decisions.
- Document activation here means enabled storage access, distinct from a user gesture. A stored permission alone does not establish current document access; the API considers revocation and masks denied permission-query state.
- This record focuses on HTTP cookies. Non-cookie extensions, browser parity and deployed conformance are not established by this review.
Sources and provenance
- The Storage Access API Privacy Community Group · reviewed 2026-10-04
- Storage Access Headers Privacy Community Group · reviewed 2026-10-04
Record reviewed 2026-10-04. Snapshot d5550c789111. Open the complete JSON contract.