What is an Access-Control-Allow-Credentials header?
Tells the browser whether the response can be shared when the request was made with credentials (cookies, auth).
This header tells the browser whether a cross-origin response is allowed to be read when the request included cookies or other credentials - and critically, it can never be paired with a wildcard Access-Control-Allow-Origin, which is one of the most common CORS misconfigurations on real websites. Getting the combination wrong either breaks legitimate authenticated cross-origin requests or opens a security hole, so it's worth verifying explicitly rather than assuming CORS 'just works' once Allow-Origin is set.
Common use case
A frontend on a separate subdomain making cookie-authenticated cross-origin requests needs the API to send Access-Control-Allow-Credentials: true, or the browser will refuse to expose the response even though the server responded successfully.
Example
Access-Control-Allow-Credentials: trueHistory
Defined as part of the CORS specification, standardised by the W3C starting around 2014.
Did you know?
It's a boolean that only ever has one valid value when present - true. There's no equivalent "false" value; the header is simply omitted to deny credentialed access.