# Same-Site vs Same-Origin

> Site and origin are not the same. Learn how eTLD+1 and the Public Suffix List define same-site, and why it decides SameSite cookie and CORS behavior.

Source: https://howhttpworks.com/glossary/same-site
Last reviewed: 2026-10-04

> **TL;DR:** A **site** is the registrable domain (eTLD+1), so `app.example.com` and `api.example.com` are the same site but different origins. CORS cares about origin; `SameSite` cookies care about site.

Two URLs are same-site when they share a registrable domain, also called eTLD+1: the effective top-level domain plus one more label. The effective TLD comes from the Public Suffix List, a maintained list of suffixes under which anyone can register names. Same-site is a looser test than same-origin, and mixing the two up causes most SameSite and CORS confusion.

## Worked examples

| A | B | Same-site? | Same-origin? |
| --- | --- | --- | --- |
| `https://app.example.com` | `https://api.example.com` | Yes | No |
| `https://example.com` | `https://example.com:8443` | Yes | No |
| `https://example.com` | `http://example.com` | Depends (see below) | No |
| `https://shop.example.co.uk` | `https://blog.example.co.uk` | Yes | No |
| `https://alice.github.io` | `https://bob.github.io` | No | No |

`co.uk` and `github.io` are both on the Public Suffix List, so `example.co.uk` and `alice.github.io` are the registrable domains, not `co.uk` or `github.io`. You cannot find this by counting dots; you need the list.

## Where each one applies

```http
GET /account HTTP/1.1
Host: api.example.com
Origin: https://app.example.com
Sec-Fetch-Site: same-site
Cookie: session=abc123
```

- **Origin decides CORS.** This request is cross-origin, so the response needs `Access-Control-Allow-Origin`.
- **Site decides cookies.** It is same-site, so a `SameSite=Strict` cookie is still attached.
- **`Sec-Fetch-Site`** is the request header that tells the server which relationship the browser computed: `same-origin`, `same-site`, `cross-site` or `none`.

## Non-obvious facts

- The HTML Standard defines both "same site" (scheme must match) and "schemelessly same site". Which one a feature uses varies, so `http://` to `https://` on the same domain is cross-site for some checks and same-site for others. Test in the browsers you support.
- Sibling subdomains are mutually trusted for SameSite purposes. An XSS hole on `blog.example.com` can send authenticated requests to `app.example.com` that SameSite will not block.
- Hosting platforms that give each customer a subdomain only stay safe because they are on the Public Suffix List.

## Go deeper

- [SameSite cookie attribute](https://howhttpworks.com/cookies/same-site)
- [Origin](https://howhttpworks.com/glossary/origin)
- [CORS guide](https://howhttpworks.com/guides/cors)
- [Cookie security guide](https://howhttpworks.com/guides/cookie-security)
