Documentation

Cross-domain visitors

How a Pro site keeps one visitor across its own domains with the _oa link parameter, and where that stops working.

What it does

A Pro site can span several domains: a shop on example.com and its checkout on example-pay.com, say. Subdomains of one domain already share the visitor id through the cookie. Separate domains cannot share a cookie, so the tracker carries the id across in the link the visitor follows.

It works for every domain in the site's allowed domains (Settings → General). There is nothing else to set up.

How the _oa parameter works

  • When a visitor clicks a link, middle-clicks it or submits a form that goes to another of your domains, the tracker adds _oa=… to that address at that moment. Links on the page are not rewritten in advance, so a copied or right-clicked link carries nothing.
  • The value holds the visitor's signed id, the time, and a short check of the browser (its user agent, timezone offset and language). No name, address or fingerprint.
  • On the destination, the tracker removes _oa from the address bar before anything records the page, and accepts it only if the visitor arrived from another of your listed domains (so a page that sends no referrer, with Referrer-Policy: no-referrer, carries nothing), it is about two minutes old or less, and the browser check matches.
  • Load oa.js before any other script that reads the page address: the tracker removes _oa when it starts, and a script running earlier could record it.
  • An accepted id replaces any local one: it is the same person who just clicked. An invalid or stale value is removed and ignored.
  • Our servers verify the signature on every event, so a forged or altered value can never plant an id; at worst the visitor is counted as in Light.
  • _oa is also stripped from stored page addresses, so it never shows in your reports.

Consent travels with the link. Both domains belong to one site and one owner, so a visitor who said yes on the first domain is remembered on the second.

Where it stops working

  • A visitor who types the second domain, or opens it from a bookmark or another app, arrives without the parameter and starts as a new visitor there. Joining them would take third-party cookies or fingerprinting, which the tracker does not use.
  • A visitor on two devices is two visitors.
  • In-app browsers keep separate storage from the phone's main browser, so a visitor who moves between them looks new.
  • A link shared and opened more than about two minutes later is too old, which is deliberate: it keeps a forwarded link from merging two people.

Signed-in visitors are joined anyway

If your site calls identify() on both domains, the signed-in visitor is one person in your data however they arrived.