Skip to main content

Frontend engineering · Networking

Cross-Origin Resource Sharing

Also called: CORS, CORS error, Same-origin policy, Cross-origin request

For security, browsers only allow requests to the same origin by default. Calling an API on another domain or port needs that server's explicit permission, or you get a CORS error.

In detail

Browsers have a security rule called the same-origin policy: two addresses are the same origin only if the protocol, domain, and port all match. If your page is on localhost:5173 and the API is on localhost:8080, the ports differ, so it's cross-origin. It's like a building's front desk: the resident (the API server) has to register visitors in advance, or the security guard (the browser) won't let them in.

When the console says "blocked by CORS policy," the API itself usually isn't broken. The browser blocked the response because of this rule. The real fix is for the API server to declare in its response headers that your domain is allowed. Frontend code can't change this rule.

During development, people often get around it with the dev server's proxy: the browser requests a same-origin address, and the dev server forwards it to the real API. The proxy only works locally, so before launch, have the backend set up the allowed domains.

Developer info
Term ID
eng-cors
DOM selectors
No DOM cues. This concept isn't detected directly on a page.
Priority
1 · when several match at the same level, the higher priority wins
Version
v1 · updated Sep 29, 2026