{
  "id": 13733402,
  "title": "CORS Explained: Why Your API Requests Fail",
  "url": "https://urgent.news/2026/10/11/cors-explained-why-your-api-requests-fail",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-10-11T14:26:55.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/rasimcarkci/cors-explained-why-your-api-requests-fail-244o"
  },
  "original_language": "en",
  "account": "Cross-Origin Resource Sharing (CORS) is a security feature in web browsers that regulates how web pages access resources from a different origin than the one the page was loaded from. This prevents malicious websites from stealing sensitive data from other sites. CORS does not block requests; it merely prevents JavaScript from reading the response if the server has not explicitly allowed the origin.\n\nTwo URLs are considered to have the same origin only if their protocol, domain, and port are identical. For instance, https://app.example.com and https://api.example.com are considered cross-origin, even though they share the same domain, because their protocols differ. Subdomains are also treated as different origins.\n\nThere are two types of cross-origin requests: simple requests and preflight requests. Simple requests are GET, POST, or HEAD methods using safe headers like Accept, Accept-Language, Content-Language, or Content-Type (application/x-www-form-urlencoded, multipart/form-data, or text/plain). If a request does not fall into this category, such as those using PUT, DELETE, Authorization headers, or custom headers, it triggers a preflight request.\n\nA preflight request is an automatic OPTIONS request sent by the browser before the actual request. The server must respond with the correct CORS headers for the browser to proceed with the request. The server's response includes headers such as Access-Control-Allow-Origin, Access-Control-Allow-Methods, Access-Control-Allow-Headers, Access-Control-Allow-Credentials, and Access-Control-Max-Age.\n\nThe Access-Control-Allow-Origin header specifies which origins are allowed to read the response. The wildcard (* ) can be used for public read-only APIs, but it has limitations. Specifically, you cannot use the wildcard when cookies, HTTP authentication, or a TLS client certificate are included in the request. In such cases, the server must explicitly set Access-Control-Allow-Origin to the specific origin and set Access-Control-Allow-Credentials to true.\n\nTo fix CORS issues, the backend must be configured to include the appropriate CORS headers. For example, in PHP, you can specify allowed origins and credentials, set the necessary headers, and handle preflight requests. In Node.js with Express, you can use the cors middleware to configure CORS settings.",
  "summary": "You fetch an API from JavaScript and get a cryptic \"blocked by CORS policy\" error. Nothing in your code is wrong — it's the browser enforcing a security rule. Here is exactly what CORS is, why it exists, and how to fix it. Originally published on MoreOnlineTools Blog . What Is CORS and Why Does It Exist? CORS stands for Cross-Origin Resource Sharing . It is a browser security mechanism that…",
  "key_points": [
    "CORS is a web browser security feature regulating cross-origin resource access.",
    "Simple requests include GET, POST, or HEAD methods with safe headers.",
    "Servers must respond with correct CORS headers for preflight requests."
  ],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}