Guides
CORS guides
41 guides cover exact browser CORS error messages, every Access-Control header, preflight failures, and server setup for Express, Django, Flask, FastAPI, Spring Boot, Laravel, Hono and Fastify, plus S3, API Gateway, Azure and Cloudflare Workers.
All guides
41 guides- Diagnose an errorDiagnose and fix a CORS errorInspect the failing network entry, identify the missing header, and apply the fix to the layer you control.Read the guide
- Understand the rulesHow cross-origin resource sharing worksReview the browser enforcement model, origin comparisons, and the headers required for cross-origin access.Read the guide
- Diagnose an errorWhy no-cors returns an opaque responseLearn why setting opaque mode hides the response body and status code from JavaScript callers.Read the guide
- Diagnose an errorWhy a request works in Postman but not in browser scriptsIsolate why tools without origin restrictions succeed while browser fetch calls fail on the same URL.Read the guide
- Diagnose an errorFix a CORS preflight failureFind why the OPTIONS probe returned a bad status code or rejected your request method and headers.Read the guide
- Decide the architectureChoosing between a CORS proxy and your own backendCompare public proxies, private forwarders, and custom backends against your security requirements.Read the guide
- CORS headersAccess-Control-Allow-CredentialsWhy true is the only valid value, how the client opts in, and why wildcards break credentialed requests.Read the guide
- CORS headersAccess-Control-Allow-HeadersThe preflight-only header that lists which request headers the actual cross-origin request may carry.Read the guide
Staring at headers right now?
Check pasted headers locally, or send a live request from this browser.
Building with a specific stack?