What is an Access-Control-Allow-Methods header?
Lists which HTTP methods are allowed when accessing the resource in a cross-origin request.
Access-Control-Allow-Methods spells out which HTTP methods (GET, POST, DELETE, and so on) a website's CORS policy permits for cross-origin requests to a given endpoint. Forgetting to list a method your frontend actually uses - PATCH is a common one to miss - will pass every server-side test you run directly while quietly failing for every browser-based client, which is exactly why CORS deserves its own explicit check.
Common use case
An API allowing cross-origin GET and POST but not DELETE lists only those two methods here, so the browser blocks a cross-origin DELETE attempt before it ever reaches the server.
Example
Access-Control-Allow-Methods: GET, POST, PUT, DELETEHistory
Defined as part of the CORS specification, standardised by the W3C starting around 2014.
Did you know?
GET, HEAD, and POST with simple content types never trigger a preflight at all - this header only comes into play once a request uses a method like PUT, DELETE, or PATCH.