Hardware FixRecommendedDevice not working? Your driver may be the problemCheck updates for common hardware issues.Fix DriversOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsClean PCRecommendedOne scan can reveal what keeps slowing WindowsLook for cleanup and repair opportunities.Run Scan×
Skip to content
World desk4 min

CORS Explained: Why Your Browser Blocks Your API

CORS lets an API control which browser origins can read its responses. Learn to distinguish a failed preflight from a response blocked after the request, then configure server headers safely.
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Your browser can send a request to an API and still refuse to give the response to your page’s JavaScript. That is CORS: a browser-enforced rule for sharing cross-origin responses, controlled by permission headers from the API server. If the request needs a preflight and that check fails, the browser stops before sending the actual request.

What CORS blocks—and what it does not

Browsers restrict scripts from freely reading responses from a different origin under the same-origin policy. An origin is the combination of scheme, host, and port. For example, a page at https://app.example.com and an API at https://api.example.com are cross-origin because their hosts differ; changing only the port or scheme also creates a different origin.

Cross-Origin Resource Sharing (CORS) lets an API server grant selected origins permission to share responses with browser scripts using HTTP response headers. The browser checks those headers. CORS is not a JavaScript permission switch, browser extension, or network firewall, and it is not authentication or authorization.

A CORS message therefore does not by itself tell you whether the API received the request. For a request that does not require preflight, the browser may send it and then withhold its response from JavaScript. A failed preflight, by contrast, prevents the browser from sending the actual request.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

When the browser sends an OPTIONS preflight

Cross-origin fetch() uses CORS by default, but not every request triggers a preflight. A request can require one when its method or manually set headers fall outside the CORS safelist. The browser first sends an OPTIONS request describing the intended method and headers. The API must authorize them before the browser proceeds.

In the Network panel, inspect the preflight request’s Origin, Access-Control-Request-Method, and Access-Control-Request-Headers. Its response needs suitable permissions in Access-Control-Allow-Origin, Access-Control-Allow-Methods, and Access-Control-Allow-Headers. A missing or mismatched permission means the browser will not send the actual request.

Rank #2
Sale
HTML and CSS: Design and Build Websites
  • HTML CSS Design and Build Web Sites
  • Comes with secure packaging
  • It can be a gift option

How to diagnose a CORS failure

  1. Compare origins. Check the page’s address and the API URL, including scheme, host, and port. If any differs, the request is cross-origin.
  2. Inspect the Network panel. Look for an OPTIONS request. If one appears, check whether it succeeded and whether the actual request followed it.
  3. Compare requested and allowed values. For a preflight, check the requested method and headers against the server’s corresponding allow headers, as well as the allowed origin.
  4. Check the actual response. Even when the API returns a successful HTTP status, the browser will not share the response with JavaScript unless that response passes the CORS check, including an appropriate Access-Control-Allow-Origin.
  5. Check credentials separately. If the request uses cookies or other credentials, verify the caller’s credentials setting, the server’s credential and origin headers, and whether browser cookie policy permits the cookie.

Page JavaScript receives only a generic failure rather than detailed CORS diagnostics. MDN notes that “CORS failures result in errors but for security reasons, specifics about the error are not available to JavaScript.” Use the browser developer console and Network panel to identify the failure instead of trying to catch a more informative CORS exception in application code. MDN’s CORS guide explains the browser messages and request flow.

Configure the API for the access you intend

Public resources without credentials

If a resource is intentionally public to browser code on every origin and does not use credentials, the server may return Access-Control-Allow-Origin: *. Apply that permission only to the resources that need it; it does not make an API private or secure.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Restricted resources

For an API intended for particular sites, validate the incoming Origin against a trusted allowlist and return the matching allowed origin only when it passes validation. Do not blindly copy any caller-supplied Origin into the response. Limit CORS permissions to the methods and headers the resource needs. MDN’s practical CORS guidance covers restricting origins and resources.

Requests that include credentials

Fetch credentials default to same-origin. To request credentials cross-origin, the caller must opt in, for example with credentials: "include". The server must return Access-Control-Allow-Credentials: true and an explicit matching Access-Control-Allow-Origin; * cannot authorize a credentialed response. Preflight requests themselves do not include credentials, but the preflight response must permit credentials for the actual credentialed request to proceed.

Rank #4
Sale
Web Design with HTML, CSS, JavaScript and jQuery Set
  • Brand: Wiley
  • Set of 2 Volumes
  • A handy two-book set that uniquely combines related technologies Highly visual format and accessible language makes these books highly effective learning tools Perfect for beginning web designers and front-end developers

These headers do not override cookie rules. SameSite attributes and browser third-party-cookie policies can still prevent a cookie from being sent. CORS permission and cookie delivery are separate checks. See MDN’s Fetch API guide for the Fetch credentials behavior.

Dynamic origin selection and caching

If the server selects an allowed origin dynamically, include Vary: Origin in the response. It tells intermediary caches that the response can differ depending on the request’s Origin, helping prevent a response authorized for one origin from being reused for another.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Why no-cors is not a typical API fix

Setting mode: "no-cors" does not grant page JavaScript access to a blocked API response. It produces an opaque response whose headers and body are unavailable to the script, and it restricts which methods and headers the request can use. Fix the server’s CORS response when browser code is meant to read the API result.

CORS does not replace API security

CORS controls whether browser JavaScript can read a cross-origin response; it does not replace authentication, authorization, or CSRF defenses. Some cross-origin requests can still be sent even when the browser withholds their responses. The server must enforce access controls for sensitive operations independently of its CORS policy. The Fetch Standard and MDN’s CORS documentation describe the browser’s response-sharing model.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More from the Wire

  1. World desk4 min
    How to Spot an AI Voice Scam Before Sending MoneyDon’t rely on how a caller sounds. Pause, call back through a known number, and verify the emergency with another trusted person before sending money.
  2. Mountain View desk4 min
    Google’s SynthID Detector: How to Check AI-Generated Images, Video and AudioGoogle’s SynthID Detector looks for an embedded watermark in supported images, video and audio. Here is what its results do—and do not—show.
  3. Redmond desk20 min
    How to create a link to File or Folder in Windows 11Windows 11 gives you several ways to point to a file or folder without moving or duplicating it. You can create a desktop shortcut,…
Recommended PC Tool
Recommended PC Tool
Windows Errors? Fix Them Before They SpreadFree repair scan
Crashes, No Sound, or Screen Glitches?Free driver scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.