Limited Availability
Security
id: iframe-credentialless
Credentialless iframes
The
credentialless attribute for the <iframe> HTML element loads third-party content in an ephemeral context and does not send any credentials such as cookies. When using cross-origin isolation, this allows you to embed content that does not send Cross-Origin-Embedder-Policy headers.
Baseline Status:
This feature is currently Limited and is missing in at least one major browser engine.
Desktop Browser Engine Support
Google Chrome
110
Supported
Mozilla Firefox
—
Unsupported
Apple Safari
—
Unsupported
Microsoft Edge
110
Supported
Mobile Browser Engine Support
Chrome Android
110
Firefox Android
—
Safari iOS
—
Specifications and References