How the web works · Concept

CORS

The browser rule that decides whether a page on one site may read responses from another site, and the reason behind the common 'blocked by CORS policy' error.

Requests and responses · updated

How it works

Browsers apply the same-origin policy: a script on app.example.com cannot read a response from api.example.net, which stops a malicious page from quietly reading your email or bank account in another tab. CORS is how a server opts in. It sends headers such as Access-Control-Allow-Origin naming the sites allowed to read its responses, and for anything beyond a simple request (a PUT or DELETE, a JSON body, custom headers) the browser first sends an OPTIONS 'preflight' request to ask permission.

CORS is enforced only by browsers. Servers, scripts and tools such as curl ignore it, so it is not a security wall around an API; authentication does that job. The fix for a CORS error belongs on the server: allow the specific front-end origin rather than '*', especially when cookies are involved, where a wildcard is not allowed anyway.

More in How the web works

Requests and responses

All 20 How the web works terms

Crafted in the dark. Shipped to the world.

Tell us what you are building. You get a private project space with a proposal and a line-by-line quote within a day.