API20-30 min
CORS Setup Implementation
This guide explains origin allowlists, credentials, preflight handling, local dev URLs, production domains, and common CORS mistakes.
Node.jsExpressBrowser APIs
Prerequisites
- A frontend URL and backend URL that may be on different origins.
- An Express API.
- A list of production domains allowed to call your API.
- Knowledge of whether your auth uses cookies or Authorization headers.
1
Install CORS middleware
Implementation snippet
npm install cors
npm install -D @types/cors2
Create an origin allowlist
Implementation snippet
const allowedOrigins = [
"http://localhost:5173",
"http://localhost:3000",
"https://app.example.com",
];3
Configure CORS
- Allow requests with no origin for server-to-server tools if needed.
- Allow only known frontend origins.
- Enable credentials only when using cookies or HTTP auth.
- List required headers and methods explicitly for predictable preflight behavior.
Implementation snippet
import cors from "cors";
app.use(cors({
origin(origin, callback) {
if (!origin || allowedOrigins.includes(origin)) return callback(null, true);
callback(new Error("Not allowed by CORS"));
},
credentials: true,
methods: ["GET", "POST", "PUT", "PATCH", "DELETE", "OPTIONS"],
allowedHeaders: ["Content-Type", "Authorization"],
}));4
Call the API from the frontend
Implementation snippet
await fetch("https://api.example.com/api/me", {
credentials: "include",
headers: { Authorization: `Bearer ${accessToken}` },
});Note: Use `credentials: "include"` only when cookies are part of the auth flow.
5
Common mistakes
Checklist
- Do not use `origin: *` with `credentials: true`.
- Do not forget localhost ports during local development.
- Do not rely on CORS as backend authorization.
- Do not add every domain dynamically without validation.
6
Verify CORS
- Open the frontend on the allowed origin and call a protected endpoint.
- Confirm OPTIONS preflight returns 204 or 200.
- Try the same request from an unlisted origin and confirm it fails.
- Check cookie auth in a production-like HTTPS environment.