Skip to main content
Resources
Web Platform
Dive into the web platform, at your pace.
HTML
CSS
JavaScript
User experience
Learn how to build better user experiences.
Performance
Accessibility
Identity
Learn
Get up to speed on web development.
Learn HTML
Learn CSS
Learn JavaScript
Learn AI
Learn Performance
Learn Accessibility
More courses
Additional resources
Explore content collections, patterns, and more.
AI and the web
Explore
PageSpeed Insights
Podcasts & shows
Developer Newsletter
About web.dev
Discover
Baseline
How to use Baseline
Blog
Case Studies
/
English
Deutsch
Español – América Latina
Français
Indonesia
Italiano
Polski
Português – Brasil
Tiếng Việt
Türkçe
Русский
עברית
العربيّة
فارسی
हिंदी
বাংলা
ภาษาไทย
中文 – 简体
中文 – 繁體
日本語
한국어
Sign in
Articles
AI and the web
Fast load times
Learn Core Web Vitals
Identity
Progressive Web Apps
Payments
Notifications
How to optimize INP
Network reliability
React
Animations
Mini apps
Media
Safe and secure
WebAssembly
Devices
Easily discoverable
Test automation
Angular
Resources
More
AI and the web
Fast load times
Learn Core Web Vitals
Identity
Progressive Web Apps
Payments
Notifications
How to optimize INP
Network reliability
React
Animations
Mini apps
Media
Safe and secure
WebAssembly
Devices
Easily discoverable
Test automation
Angular
Discover
Baseline
How to use Baseline
Blog
Case Studies
Understand security basics
Security should not be so scary!
What are security attacks?
Understanding "same-site" and "same-origin"
Security headers quick reference
Secure connections with HTTPS
Why HTTPS matters
Enabling HTTPS on your servers
What is mixed content?
Fixing mixed content
When to use HTTPS for local development
How to use HTTPS for local development
Prevent info leaks
Browser sandbox
Same-origin policy
Cross-Origin Resource Sharing (CORS)
Making your website "cross-origin isolated" using COOP and COEP
Why you need "cross-origin isolated" for powerful features
Protect your resources from web attacks with Fetch Metadata
Protect websites from XSS
Prevent DOM-based cross-site scripting vulnerabilities with Trusted Types
Mitigate cross-site scripting (XSS) with a strict Content Security Policy (CSP)
Securely hosting user data in modern web applications
Protect users from tracking
Understanding cookies