# CORS (Cross-Origin Resource Sharing)

URL: https://softwaredictionary.org/terms/cors
Category: Web Development
Last updated: 2026-09-29
Pronunciation: KORZ

In short: CORS is a browser security mechanism that lets a server declare which other websites may read its responses when they make requests from JavaScript.

## What is CORS?

Browsers enforce the same-origin policy: JavaScript running on one origin, meaning a specific combination of scheme, domain, and port like `https://app.example.com`, cannot read responses from a different origin by default. CORS is the standard way for a server to relax that rule safely, by sending HTTP headers that say which origins are allowed.

When a page calls `fetch()` on another origin, the browser adds an `Origin` header to the request. If the response includes a matching `Access-Control-Allow-Origin` header, the browser hands the data to the script; otherwise it blocks the response and logs a CORS error. For requests that could change data, such as those using `PUT`, `DELETE`, or custom headers, the browser first sends an `OPTIONS` preflight request to ask permission.

Think of CORS as a guest list written by the server and checked by the browser acting as the bouncer. The key detail is that the browser enforces it, not the server: tools like `curl` and other servers ignore CORS entirely, which is why a request can work in a terminal but fail in the browser.

A common mistake is treating CORS as protection for an API. CORS does not stop anyone from sending requests; it only controls which web pages can read the responses in a browser, so real protection still requires authentication and authorization. Allowing every origin with `*` on private APIs is risky, and browsers refuse to combine `*` with credentials such as cookies.

## Key takeaways

- Browsers block cross-origin reads by default under the same-origin policy.
- CORS headers from the server tell the browser which origins are allowed.
- Preflight `OPTIONS` requests check permission before certain requests.
- CORS is enforced by browsers, not by servers or command-line tools.
- CORS errors are fixed on the server, not in front-end code.

## Example: Allowing one origin to call an API (Express)

```javascript
app.use((req, res, next) => {
  // Only this front end may read responses in the browser
  res.setHeader("Access-Control-Allow-Origin", "https://app.example.com");
  res.setHeader("Access-Control-Allow-Methods", "GET, POST, PUT, DELETE");
  res.setHeader("Access-Control-Allow-Headers", "Content-Type, Authorization");

  // Answer preflight requests without running the route
  if (req.method === "OPTIONS") return res.sendStatus(204);
  next();
});
```

## Frequently asked questions

**How do I fix a CORS error?**

Configure the server that owns the API to return an `Access-Control-Allow-Origin` header that includes your front end's origin, and to answer preflight `OPTIONS` requests. The error cannot be fixed from browser-side JavaScript alone, although a same-origin proxy is a common workaround during development.

**Does CORS protect my API from attackers?**

No. CORS only controls whether browsers let web pages read responses; attackers can still call your API directly with other tools. You still need authentication, authorization, and CSRF protection.

**What is a preflight request?**

A preflight is an automatic `OPTIONS` request the browser sends before certain cross-origin requests to check whether the server allows the method and headers. If the server does not approve, the real request is never sent.

## Sources

- [Fetch Standard: CORS protocol](https://fetch.spec.whatwg.org/#http-cors-protocol)
- [MDN: Cross-Origin Resource Sharing (CORS)](https://developer.mozilla.org/en-US/docs/Web/HTTP/Guides/CORS)

---

Software Dictionary: https://softwaredictionary.org/ · https://softwaredictionary.org/llms.txt
