How HTTP Works

Glossary Term

Same-Site vs Same-Origin

Site and origin are not the same. Learn how eTLD+1 and the Public Suffix List define same-site, and why it decides SameSite cookie and CORS behavior.

Reviewed 2 min readintermediate3 sourcesMarkdown
On this page

TL;DR: A site is the registrable domain (eTLD+1), so app.example.com and api.example.com are the same site but different origins. CORS cares about origin; SameSite cookies care about site.

Two URLs are same-site when they share a registrable domain, also called eTLD+1: the effective top-level domain plus one more label. The effective TLD comes from the Public Suffix List, a maintained list of suffixes under which anyone can register names. Same-site is a looser test than same-origin, and mixing the two up causes most SameSite and CORS confusion.

Worked examples

ABSame-site?Same-origin?
https://app.example.comhttps://api.example.comYesNo
https://example.comhttps://example.com:8443YesNo
https://example.comhttp://example.comDepends (see below)No
https://shop.example.co.ukhttps://blog.example.co.ukYesNo
https://alice.github.iohttps://bob.github.ioNoNo

co.uk and github.io are both on the Public Suffix List, so example.co.uk and alice.github.io are the registrable domains, not co.uk or github.io. You cannot find this by counting dots; you need the list.

Where each one applies

GET /account HTTP/1.1
Host: api.example.com
Origin: https://app.example.com
Sec-Fetch-Site: same-site
Cookie: session=abc123
  • Origin decides CORS. This request is cross-origin, so the response needs Access-Control-Allow-Origin.
  • Site decides cookies. It is same-site, so a SameSite=Strict cookie is still attached.
  • Sec-Fetch-Site is the request header that tells the server which relationship the browser computed: same-origin, same-site, cross-site or none.

Non-obvious facts

  • The HTML Standard defines both “same site” (scheme must match) and “schemelessly same site”. Which one a feature uses varies, so http:// to https:// on the same domain is cross-site for some checks and same-site for others. Test in the browsers you support.
  • Sibling subdomains are mutually trusted for SameSite purposes. An XSS hole on blog.example.com can send authenticated requests to app.example.com that SameSite will not block.
  • Hosting platforms that give each customer a subdomain only stay safe because they are on the Public Suffix List.

Go deeper

Frequently asked questions

What is the difference between same-site and same-origin?

Same-origin requires identical scheme, host and port. Same-site only requires the same registrable domain (eTLD+1), so subdomains and different ports are same-site but cross-origin.

What is eTLD+1?

It is the effective top-level domain plus one label, such as example.com or example.co.uk. The effective TLD is determined by the Public Suffix List, not by counting dots.

Are alice.github.io and bob.github.io same-site?

No. github.io is on the Public Suffix List, so each subdomain is its own site. That is what stops one user page from sharing cookies with another.

Does CORS use same-site or same-origin?

CORS and the same-origin policy use origin. SameSite cookies and the Sec-Fetch-Site header use site.

Sources

  1. MDN Web Docs: Sitedeveloper.mozilla.org
  2. Public Suffix Listpublicsuffix.org
  3. WHATWG HTML Standard: Sitehtml.spec.whatwg.org

Keep going

Browse /search