Glossary

What Is CORS? Why "Blocked by CORS Policy" Happens and How to Debug It

Definition: CORS (Cross-Origin Resource Sharing)

CORS (Cross-Origin Resource Sharing) is the browser mechanism that lets a server say which other origins may read its responses. By default JavaScript cannot read a response from a different origin; the server opts in with headers such as Access-Control-Allow-Origin. A "blocked by CORS policy" error means the browser refused to hand the response to your code.

Also called: Cross-Origin Resource Sharing, CORS error, CORS policy, preflight request

What counts as a different origin

An origin is scheme + host + port. https://app.example.com and https://api.example.com are different origins, and so are http://localhost:5173 and http://localhost:3000.

Simple requests vs preflight requests

A "simple" GET or POST with basic headers is sent straight away, and the browser checks the response headers afterwards. Anything else, such as PUT, DELETE, a JSON Content-Type or an Authorization header, triggers a preflight: the browser first sends OPTIONS asking permission, and only sends the real request if the server agrees.

HeaderSent byPurpose
OriginBrowserWhich origin is asking
Access-Control-Allow-OriginServerWhich origin may read the response (* or an exact origin)
Access-Control-Allow-MethodsServer (preflight)Allowed methods
Access-Control-Allow-HeadersServer (preflight)Allowed request headers
Access-Control-Allow-CredentialsServerWhether cookies may be sent; cannot be combined with *

The most common CORS errors

  • No `Access-Control-Allow-Origin` header: the server does not know about your origin.
  • Wildcard with credentials: * is not allowed when the request includes cookies.
  • Preflight fails: the OPTIONS route returns 404 or 401, often because auth middleware runs before CORS.
  • Redirect during preflight: preflight responses must not redirect.

Unblocking development safely

The correct fix is always on the server. While you wait for it, or when you are testing against a third-party API, you have three options: a dev-server proxy (for example Vite's server.proxy), a browser tool that adds the headers for your session only, or a CORS forwarder.

ProxyCeptor supports the last two: a rule can add Access-Control-Allow-* response headers in your browser, and the server-side forwarder relays the call with permissive CORS headers. See how to bypass CORS and modify response headers.

Never disable web security in your everyday browser profile. Use a rule scoped to one API pattern and turn it off when you are done.

Frequently asked questions

Is CORS a server or a browser problem?

Both. The browser enforces it, but only the server can fix it properly by sending the right headers. Tools like Postman or curl ignore CORS because they are not browsers.

Why does my request work in Postman but fail in the browser?

Postman does not enforce CORS. The browser does, so the server must allow your front-end origin.

Does CORS protect my API?

No. CORS protects users' browsers from reading data they should not. Anyone can call your API directly with curl, so use real authentication.

Keep learning

Intercept your first request in under a minute

Create a free ProxyCeptor account to mock, delay, block and rewrite API traffic, then share the same rules with your team.