COOP COEP CORP Checker
Connected Diagnostic
COOP / COEP / CORP Checker
Inspect the three cross-origin isolation policies as a set. The tool explains what is present, whether the COOP/COEP pair is configured for isolation, and why blindly tightening these headers can break legitimate integrations.
Missing is not automatically broken
Cross-origin isolation is useful when a site needs capabilities that depend on it, but most ordinary websites should not add these headers merely to improve a security score. COOP can affect popup and opener relationships; COEP can stop cross-origin resources loading unless the resource or request mode is compatible.
I would use this check when enabling cross-origin isolation deliberately, debugging SharedArrayBuffer-related requirements, or reviewing a security-header deployment. Treat CORP as a resource policy, not a checkbox that belongs on every response.
