Prepare Salesforce Canvas apps for the new web browser restrictions on third-party cookies. Several major browsers have already disabled third-party cookies by default, including Mozilla Firefox, Apple Safari, and Brave. In January 2024, Google started a gradual rollout of its Privacy Sandbox initiative, which phased out support for third-party cookies in its Chrome browser and enforces storage partitioning in third-party contexts. However, in July 2024, Google reversed its plans to completely block third-party cookies. Instead, Chrome users can decide whether to block third-party cookies. Despite Google’s recent reversal, Salesforce moves ahead with its plans to end reliance on third-party cookies, such as moving Setup pages to the new *.salesforce-setup.com domain. Other popular browsers already block third-party cookies by default, and Salesforce expects that many users will choose to block third-party cookies due to privacy concerns.
Third-party cookies are the main mechanism that enables cross-site tracking. When Canvas apps are exposed in Salesforce via an iframe, the content may not load properly because the content is served from a different domain. To avoid problems late in development, test Canvas apps in a Salesforce container early. To design applications that don’t rely on cookies, session storage, or local storage to track users, build your Canvas apps as single-page applications (SPAs).
Salesforce Canvas doesn’t inherently require third-party cookies, so the impact of the browser restrictions is subject to your implementation of Salesforce Canvas. Canvas also doesn’t provide a solution if storage is accessed in a third-party context. We recommend that Canvas apps avoid reliance on third-party cookies and unpartitioned storage. See Alternatives to Cookies for User Tracking in Salesforce Help.
In the meantime, we recommend testing all Canvas apps to ensure that these browser restrictions don’t impact critical business workflows. If you use Google Chrome, follow Google’s testing guidance to validate key Salesforce Canvas scenarios with third-party cookies disabled. If you determine that your Canvas app is affected, consider applying the third-party cookie policies for Chrome Enterprise customers.
Salesforce Developers Blog: Prepare for the Google Chrome Privacy Sandbox Initiative
Knowledge Article: Understand How Google's Privacy Sandbox Initiative Impacts Salesforce
Salesforce Help: Test the Impact of Blocked Salesforce Session Cookies
002192971

We use three kinds of cookies on our websites: required, functional, and advertising. You can choose whether functional and advertising cookies apply. Click on the different cookie categories to find out more about each category and to change the default settings.
Privacy Statement
Required cookies are necessary for basic website functionality. Some examples include: session cookies needed to transmit the website, authentication cookies, and security cookies.
Functional cookies enhance functions, performance, and services on the website. Some examples include: cookies used to analyze site traffic, cookies used for market research, and cookies used to display advertising that is not directed to a particular individual.
Advertising cookies track activity across websites in order to understand a viewer’s interests, and direct them specific marketing. Some examples include: cookies used for remarketing, or interest-based advertising.