What Is CORS? Why "Blocked by CORS Policy" Happens and How to Debug It
CORS (Cross-Origin Resource Sharing) is the browser mechanism that lets a server say which other origins may read its responses. By default JavaScript cannot read a response from a different origin; the server opts in with headers such as Access-Control-Allow-Origin. A "blocked by CORS policy" error means the browser refused to hand the response to your code.
Also called: Cross-Origin Resource Sharing, CORS error, CORS policy, preflight request
What counts as a different origin
An origin is scheme + host + port. https://app.example.com and https://api.example.com are different origins, and so are http://localhost:5173 and http://localhost:3000.
Simple requests vs preflight requests
A "simple" GET or POST with basic headers is sent straight away, and the browser checks the response headers afterwards. Anything else, such as PUT, DELETE, a JSON Content-Type or an Authorization header, triggers a preflight: the browser first sends OPTIONS asking permission, and only sends the real request if the server agrees.
| Header | Sent by | Purpose |
|---|---|---|
Origin | Browser | Which origin is asking |
Access-Control-Allow-Origin | Server | Which origin may read the response (* or an exact origin) |
Access-Control-Allow-Methods | Server (preflight) | Allowed methods |
Access-Control-Allow-Headers | Server (preflight) | Allowed request headers |
Access-Control-Allow-Credentials | Server | Whether cookies may be sent; cannot be combined with * |
The most common CORS errors
- No `Access-Control-Allow-Origin` header: the server does not know about your origin.
- Wildcard with credentials:
*is not allowed when the request includes cookies. - Preflight fails: the
OPTIONSroute returns 404 or 401, often because auth middleware runs before CORS. - Redirect during preflight: preflight responses must not redirect.
Unblocking development safely
The correct fix is always on the server. While you wait for it, or when you are testing against a third-party API, you have three options: a dev-server proxy (for example Vite's server.proxy), a browser tool that adds the headers for your session only, or a CORS forwarder.
ProxyCeptor supports the last two: a rule can add Access-Control-Allow-* response headers in your browser, and the server-side forwarder relays the call with permissive CORS headers. See how to bypass CORS and modify response headers.
Frequently asked questions
Is CORS a server or a browser problem?
Both. The browser enforces it, but only the server can fix it properly by sending the right headers. Tools like Postman or curl ignore CORS because they are not browsers.
Why does my request work in Postman but fail in the browser?
Postman does not enforce CORS. The browser does, so the server must allow your front-end origin.
Does CORS protect my API?
No. CORS protects users' browsers from reading data they should not. Anyone can call your API directly with curl, so use real authentication.
Keep learning
Intercept your first request in under a minute
Create a free ProxyCeptor account to mock, delay, block and rewrite API traffic, then share the same rules with your team.