Glossary Web & HTTP

CORS

CORS (Cross-Origin Resource Sharing) is the browser mechanism that lets a server allow web pages from other origins to read its responses.

Last reviewed:

AdSense Placeholder
Slot: header_reference_page

In more detail

Browsers apply the same-origin policy: a script on one site may not read data from another origin unless that origin opts in with headers such as Access-Control-Allow-Origin. For non-simple requests the browser first sends an OPTIONS preflight to ask permission. CORS protects users in the browser; it does not stop other programs calling the API.

Try these tools

See also

  • Glossary HTTP
    HTTP (Hypertext Transfer Protocol) is the protocol browsers and servers use to request and send web pages, files and data.
  • Glossary Content Security Policy (CSP)
    A Content Security Policy is an HTTP header that tells the browser which sources of scripts, styles.
  • Cheat sheet HTTP Headers Cheat Sheet
    Request and response headers, Cache-Control directives, security headers, cookie attributes and CORS headers.
AdSense Placeholder
Slot: footer_leaderboard