In more detail
Browsers apply the same-origin policy: a script on one site may not read data from another origin unless that origin opts in with headers such as Access-Control-Allow-Origin. For non-simple requests the browser first sends an OPTIONS preflight to ask permission. CORS protects users in the browser; it does not stop other programs calling the API.