Skip to main content

CORS

Cross-Origin Resource Sharing

Pronunciation
KORZ
Updated 2 min read

Share this page

Send the link, quote the definition with a link back, or show it as a card on your own site.

https://softwaredictionary.org/terms/cors

In short

CORS is a browser security mechanism that lets a server declare which other websites may read its responses when they make requests from JavaScript.

What is CORS?

Browsers enforce the same-origin policy: JavaScript running on one origin, meaning a specific combination of scheme, domain, and port like https://app.example.com, cannot read responses from a different origin by default. CORS is the standard way for a server to relax that rule safely, by sending HTTP headers that say which origins are allowed.

When a page calls fetch() on another origin, the browser adds an Origin header to the request. If the response includes a matching Access-Control-Allow-Origin header, the browser hands the data to the script; otherwise it blocks the response and logs a CORS error. For requests that could change data, such as those using PUT, DELETE, or custom headers, the browser first sends an OPTIONS preflight request to ask permission.

Think of CORS as a guest list written by the server and checked by the browser acting as the bouncer. The key detail is that the browser enforces it, not the server: tools like curl and other servers ignore CORS entirely, which is why a request can work in a terminal but fail in the browser.

A common mistake is treating CORS as protection for an API. CORS does not stop anyone from sending requests; it only controls which web pages can read the responses in a browser, so real protection still requires authentication and authorization. Allowing every origin with * on private APIs is risky, and browsers refuse to combine * with credentials such as cookies.

At a glance

A cross-origin call with CORS: a page on https://a.com calls an API on https://b.com. The browser first sends an OPTIONS preflight, the API allows that origin with Access-Control headers, then the browser sends the real PUT request and hands the response to the script.Browserpage on https://a.comAPIhttps://b.compreflightOPTIONS /ordersOrigin: https://a.com204 No ContentAccess-Control-Allow-Origin: https://a.comAccess-Control-Allow-Methods: PUTreal requestPUT /orders200 OKAccess-Control-Allow-Origin: https://a.comBrowser hands the data to the script
The server says which origins are allowed; the browser checks those headers and only then lets the page's script read the response.

Key takeaways

  • Browsers block cross-origin reads by default under the same-origin policy.
  • CORS headers from the server tell the browser which origins are allowed.
  • Preflight OPTIONS requests check permission before certain requests.
  • CORS is enforced by browsers, not by servers or command-line tools.
  • CORS errors are fixed on the server, not in front-end code.

Example

Allowing one origin to call an API (Express)javascript
app.use((req, res, next) => {
  // Only this front end may read responses in the browser
  res.setHeader("Access-Control-Allow-Origin", "https://app.example.com");
  res.setHeader("Access-Control-Allow-Methods", "GET, POST, PUT, DELETE");
  res.setHeader("Access-Control-Allow-Headers", "Content-Type, Authorization");

  // Answer preflight requests without running the route
  if (req.method === "OPTIONS") return res.sendStatus(204);
  next();
});

Readers ask

How do I fix a CORS error?

Configure the server that owns the API to return an Access-Control-Allow-Origin header that includes your front end's origin, and to answer preflight OPTIONS requests. The error cannot be fixed from browser-side JavaScript alone, although a same-origin proxy is a common workaround during development.

Does CORS protect my API from attackers?

No. CORS only controls whether browsers let web pages read responses; attackers can still call your API directly with other tools. You still need authentication, authorization, and CSRF protection.

What is a preflight request?

A preflight is an automatic OPTIONS request the browser sends before certain cross-origin requests to check whether the server allows the method and headers. If the server does not approve, the real request is never sent.

See also

Sources

Spotted a mistake or something missing on this page?Suggest an edit

Read a random page
Open today's review
Switch to the dark theme
Read this page in Türkçe

More

Settings