Practical guides

Test journeys with third-party cookies blocked

A visitor can express a choice in the website while their browser still blocks third-party storage. Separate the website choice from the browser’s technical capability: both need testing.

Go to the method

Diagram: identify a dependency, block storage, repeat the journey and provide a fallback.
Original method diagram.

Identify a dependency on another site

An embedded player, booking tool or login journey may use cookies in a third-party context. MDN’s documentation explains these contexts. Record the component, provider and action that depends on stored state. A different hostname alone does not fully describe how the component works.

Describe the required outcome: identifying someone, retaining a basket, selecting a slot or playing a video. Note the embedding point and fallback when the relevant state is inaccessible. A displayed page does not establish successful task completion.

Repeat a matrix of conditions

Prepare fresh sessions with third-party storage allowed and blocked, then vary the website’s consent choice. Test browsers used by the audience. Retain version, setting, date and initial state; private browsing and cookie blocking are not necessarily equivalent.

Check starting, progression, confirmation and recovery after refresh. For bookings, distinguish a displayed calendar from an actual confirmation. For login, test return from the provider and session continuity. Use test accounts and operations without placing real orders merely to assess an interface.

  • No previous state.
  • Third-party storage blocked.
  • Website choice and browser setting recorded.

Understand the limits of technical options

The Storage Access API lets embedded content request relevant storage access in supporting browsers. It does not grant universal automatic access. Handle denial, missing support and required interaction where applicable.

Partitioned storage isolates state by site context; it is not a universal mechanism for sharing login across all sites. Do not replace a blocked cookie with hidden collection. Technical permission and purpose assessment remain separate: a browser grant does not replace a required website choice.

Provide a useful way forward

When an embedded component cannot work, offer a clear action: open the provider’s page where appropriate, request a slot through another channel or read a transcript. Identify the destination and implications. The fallback should preserve information needed for the task.

Test returning to the website, cancellation, errors and repeated clicks. A new window should not trap users or lose their entered information. When booking leaves the website, explain where confirmation occurs; an enquiry received through your form does not guarantee availability.

Track announcements without treating them as universal rules

In its 17 October 2025 announcement, Google announced retirement of several Privacy Sandbox technologies including Topics and Protected Audience, while maintaining Chrome’s approach to third-party cookie choice. Avoid assuming a universal removal date or depending on an API announced for retirement. Inspect the current browser and intended API.

Link findings to the consent review, third-party resource review and acceptance log. Retest fixes with the same initial state. Dated observations can be revisited when providers or browsers change.

Content updated on October 2, 2026

Acceptance matrix to adapt to your project

These proposed checks use synthetic cases. Decide the required behaviour with the team, record the result and assign unresolved gaps before release.

Test cases, expected outcomes and useful evidence
CaseExpected outcomeEvidence to retain
A calendar appears but slot selection fails with third-party storage blocked.The failure is detected and a fallback explains how to request a slot.Repeat selection and confirmation in the blocked configuration.
Login returns from the provider but no session persists.The journey reports the problem without declaring false success.Test return, refresh and an authenticated action.
An embedded player does not load.The page retains essential information and a usable alternative.Block storage or the provider in the test environment.

Frequently asked questions

Does accepting the website banner unblock third-party storage?

No. Browser settings or protections may continue to block it. Verify both configurations and provide a useful fallback.

Does opening the provider in a tab solve every case?

No. That changes context and can help some journeys, but login, information transfer, return and confirmation require verification. Explain the alternative clearly.

Do all browsers apply the same policy?

No. Record browser, version, setting and initial state. One configuration’s result does not establish behaviour in others.