Embedded Storage Access

Storage Access in Embedded Contexts

Block third-party cookies and a cross-site iframe — a chat widget, a checkout — reads an empty document.cookie. The Storage Access API is the way back in: document.hasStorageAccess() reports whether the frame holds its unpartitioned cookies, document.requestStorageAccess() asks for them. It needs transient activation, a secure context, SameSite=None; Secure cookies and a recent first-party visit to the embedded site; sandboxed iframes also need allow-storage-access-by-user-activation. Baseline Widely available since June 2026 (Safari 11.1 10 , Firefox 65 555 , Chrome 119 1 ).

An embedded widget asking for its own cookiesJavaScript
const { state } = await navigator.permissions.query({ name: 'storage-access' });
console.log('cookie:', JSON.stringify(document.cookie), '| permission:', state);
button.onclick = async () => {                      // a genuine click is mandatory
  if (await document.hasStorageAccess()) return;
  try { await document.requestStorageAccess(); }    // may show a permission prompt
  catch (err) { return console.log('denied:', err.name); }
  console.log('granted; cookie now', JSON.stringify(document.cookie));
};
Output
cookie: "" | permission: prompt
denied: NotAllowedError

In headless Chrome 152 with third-party cookies blocked, the cookie was invisible and the request failed with nobody to answer the prompt. Storage Access Headers skip the reload a grant normally forces: a request carries Sec-Fetch-Storage-Access: inactive and the server replies Activate-Storage-Access: retry; allowed-origin=* (Chrome 133, Firefox 147, not Safari). CHIPS (Cookies) needs no permission but gives a separate jar per embedding site: use it for per-embed state, this API for one shared identity.