Slate Stats › My team › ESPN private leagues

Why a private ESPN league sometimes will not load

Short version: ESPN’s own cookie settings prevent it, in every browser, and the way around it is to ask for your login — which we will not do.

What happens when it works

A public league needs nothing. For a private one, your browser sends the ESPN session it already has — the same cookie it uses on espn.com — straight to ESPN when it asks for your league. The request goes from your machine to ESPN. It does not come through us, we never receive it, and there is no server on this site that could store it if we wanted to.

Why it does not

That is a cross-site request carrying a cookie, and the cookie decides whether a browser will send one. ESPN sets its session cookie with no SameSite attribute — measured on SWID, which comes back from espn.com as path=/; domain=espn.com and nothing else. Every current browser treats a cookie with no SameSite as Lax, and a Lax cookie is never attached to a cross-site request no matter what the site asks for.

So this is not a setting you can change and not a browser you can swap. It is ESPN’s cookie, and until ESPN marks it SameSite=None the request arrives at ESPN with no session attached. ESPN’s servers are willing — they return access-control-allow-credentials: true and name this site specifically — but the browser never sends the cookie for them to check.

We got this wrong at first, and the correction is worth stating: this page originally said private leagues worked in some browsers and not others. That is the story for third-party cookies generally, and it is true, but it is not what stops this. We had verified that ESPN permits the request and inferred the rest without checking the one attribute that decides it.

ESPN also returns 404 rather than "you are not allowed" for a league you cannot see, so a private league and a mistyped ID look identical from here. If it fails, check the number first.

What we will not do about it

There is a way around this and we have not taken it. Most tools that read private ESPN leagues ask you to open developer tools, copy two cookies called espn_s2 and SWID, and paste them into a box. That works in every browser. It also means handing your ESPN session to someone else’s server, where it can be logged, stored or leaked, and it is a live session rather than a password you can change easily.

We would rather a feature work in fewer browsers than ask for that. If your browser blocks it, a public league still works, and so does every projection on this site without connecting anything.