Skip to content
>devspeak
← glossary
level 5APIs & Communication

CORS

also: cross-origin resource sharing, cors error, cors policy, cross-origin, access-control-allow-origin

A browser safety rule: a web page can only read data from a different website if that website's server says the page is allowed to.

a bit more technical

Cross-Origin Resource Sharing. Browsers stop JavaScript on one origin (scheme, domain and port) from reading responses from another origin unless the server sends headers like Access-Control-Allow-Origin. Some requests trigger a preflight OPTIONS check first. Browsers enforce it; servers only grant permission.

picture it

A school only releases a child to adults on the parents' pickup list. The school enforces the rule, but the parents write the list. Anyone not on it leaves empty-handed.

why it matters

CORS errors confuse beginners and agents alike. Knowing the fix belongs on the server, and should list specific allowed sites, stops an agent from "fixing" it by allowing everyone.

what your agent might say
agent
The browser blocks the request because the API doesn't send Access-Control-Allow-Origin for localhost:3000. I'll add your frontend origins to the CORS allowlist.
how you might use it
you → your agent
Fix the CORS error by allowing only our production site and localhost. Don't allow every website to read our API, and explain why it was failing.
common mistake

Thinking CORS protects your server from other programs. Only browsers enforce it. Scripts and command-line tools like curl ignore it completely.