Zoho Custom Domain Cookie Errors: Fix Upload, Download & Preview Issues

Custom Domain Cookie Errors in Zoho Apps: How to Fix Upload, Download and Preview Failures

If your organisation has set up a custom domain for a Zoho product such as Zoho Connect, WorkDrive, Learn or a similar app, you may find that certain actions, particularly opening files, launching custom apps, or uploading, downloading and previewing attachments, simply refuse to work. This is a known browser limitation rather than a fault with Zoho, and it comes down to how third-party cookies are handled once a custom domain is in play.

Why the errors occur

Zoho products route certain background actions, most notably uploads, through dedicated infrastructure domains (for example upload.zoho.com) rather than through your organisation's own domain. When you access the product through a custom domain, say connect.yourcompany.com, that infrastructure domain no longer shares the same address as the one in your browser bar. Modern browsers treat any domain that doesn't match the address bar as a third party, and if third-party cookies are blocked, the request to the infrastructure domain is rejected because the session cookies never make it through.

Note: Without a custom domain, Zoho serves the product from its own zoho.com subdomain, so both the main page and the infrastructure domain sit under zoho.com and cookies are not blocked. The issue only appears once a custom domain has been configured.

Step 1: Grant access to your custom domain

The first time a user signs in through the newly configured custom URL, Zoho will present an access confirmation screen. Depending on the product, this may ask the user to tick a "Trust this website" box and select Grant Access, or to choose between allowing access for the current session only or allowing it permanently. Approving this is a one-off step per device that also authorises the other Zoho infrastructure domains the product relies on for uploads, downloads and previews, and it substantially smooths out the user experience afterwards.

Step 2: Allow third-party cookies for your custom domain

The more permanent fix is to add your custom domain to the list of sites your browser always permits to use cookies, including third-party cookies. The exact menu wording varies by browser.

Google Chrome

  1. Open the three-dot menu in the top-right corner and choose Settings.
  2. Go to Privacy and security > Site Settings, then scroll to the Content section and select Cookies and site data.
  3. Under Sites that can always use cookies, click Add, enter your custom domain, tick Including third-party cookies on this site, and confirm.

Mozilla Firefox

  1. Open the menu and select Settings (or Preferences).
  2. Under Privacy and Security, choose the Custom cookie option and deselect the Cookies checkbox so third-party cookies are not blocked.
  3. Reload all open tabs for the change to take effect.

Safari

  1. Open Safari > Preferences and switch to the Privacy tab.
  2. Deselect Block all cookies and Prevent cross-site tracking.

Microsoft Edge

  1. Click the ellipsis menu in the top-right corner and choose Settings.
  2. Go to Cookies and site permissions, then Manage and delete cookies and site data.
  3. Under the Allow section, tick Including third-party cookies on this site, enter your custom domain, and click Add.

Frequently asked questions

Why do I need to enable third-party cookies at all?

Take a custom domain such as connect.yourcompany.com as an example. When you upload a file, the request is actually sent to a separate domain, such as upload.zoho.com. Because this domain doesn't match the one in your address bar, your browser classes it as third party and blocks it unless you have explicitly allowed cookies for it.

Why does Zoho use a separate domain for uploads?

Splitting off infrastructure such as file uploads onto dedicated domains, for example upload.zoho.com, helps Zoho deliver faster and more reliable performance for those specific actions.

What actually happens behind the scenes with a custom domain?

When you visit your custom domain, Zoho sets the required session cookies against both the custom domain itself and the underlying *.zoho.com domain, so that later requests to infrastructure domains can be authenticated.

What does a browser's third-party cookie policy actually do?

Most modern browsers now block third-party cookies by default. Once that setting is active, cookies simply aren't attached when a page on your custom domain calls out to a Zoho infrastructure domain such as upload.zoho.com, so the server sees the request as unauthenticated and rejects it.

Why doesn't this happen without a custom domain?

Without a custom domain, everything, the main product page and the infrastructure domain used for uploads, sits under zoho.com. Because both are technically the same parent domain, the browser doesn't treat the cookies as third party and nothing gets blocked.

Need help? If your team is struggling with custom domain configuration or browser compatibility issues across your Zoho applications, our Zoho Consultant team can help you get it configured correctly first time. Book a discovery call with 1 Cloud Consultants.