Session stitching across the quote engines, SSO redirects and payment iframes that break single-domain GA4, with every hop walked by hand and verified.
About this service
Safari caps a cookie set client-side after a link-decorated cross-site navigation at 24 hours, and other client-side cookies at 7 days. That one rule decides most of what a cross-domain build can honestly promise, because the journeys that need stitching in banking, insurance and recruitment are exactly the ones that leave your domain, sit on somebody else's platform for eleven minutes, and come back. Before quoting, we ask for the list of domains in the journey. If the answer is one domain and its subdomains, this is a configuration change and we will say so in a reply rather than sell you a project.
The hop map:
The first deliverable maps every boundary the user crosses and what happens to identity at each one. A quote engine on a supplier's domain. An SSO redirect through Okta, Auth0 or ForgeRock that drops the referrer. A hosted payment page from Adyen, Stripe or Worldpay, sometimes an iframe and sometimes a full-page redirect, which changes the entire approach. An applicant tracking system — Workday, Greenhouse, SmartRecruiters — serving a career site from a domain your brand does not control. A paywall handing off to an identity provider. Each hop is classified: same eTLD+1, decorated link, iframe with postMessage, or unrecoverable.
The build:
GA4 cross-domain configuration for the domains that qualify, with the linker verified on the real navigation rather than in preview. Referral exclusions set so the return hop does not restart the session and re-credit the payment provider with the conversion — the most common defect we find, and the one that quietly moves revenue away from paid channels. For iframes, a postMessage bridge, because a linker cannot reach inside an iframe. For redirects through third parties that strip query parameters, a session identifier carried in the state parameter of the auth request and read back on return. Where a hop is genuinely unrecoverable we say so, mark it, and size the loss, so reporting carries an honest footnote instead of a silent hole.
Verification:
Every hop is walked by hand on Safari, on Chrome, and in an in-app browser, with the network log captured before and after. Not preview mode. Real journeys on real devices, because preview lies about exactly the cases this work exists to fix.
What we refuse:
No fingerprinting, no probabilistic matching, no device-graph vendor. Where deterministic stitching cannot cross a boundary, the boundary stays crossed and the report says so. We do not set cookies on domains our client does not control. We do not stitch across a consent boundary where the second domain runs its own banner and the visitor declined there — that visitor is two visitors, correctly. And we decline to reassemble a joined session in the warehouse after the fact when the cause is a broken hop. Fix the hop.
Who this is not for:
Anyone who needs the number to go up. Correct cross-domain tracking usually shows fewer sessions and different channel credit than the broken version it replaces, and someone has to explain that to a board. If your organisation cannot absorb a restatement of last year's channel mix, do not start here. It is also wrong for single-domain sites, and wrong for teams who want the map without the walkthrough. The walkthrough is where the defects live.