← All headersResponse header

What is an Access-Control-Allow-Origin header?

Tells the browser which origin(s) are allowed to read a cross-origin response, the core CORS header.

Access-Control-Allow-Origin is the header that actually grants (or denies) a cross-origin script permission to read a website's response - get it wrong and a browser-based client gets silently blocked from data the server technically sent back just fine. Because the failure only shows up in browser JavaScript, not in a plain server-side request, a monitor that specifically checks CORS headers on cross-origin endpoints catches a whole category of bug that a simple 'did it return 200' check will completely miss.

Common use case

A public API sets Access-Control-Allow-Origin: * so any third-party website's frontend JavaScript can call it directly from the browser without being blocked by CORS.

Example

Access-Control-Allow-Origin: https://app.example.com

History

Defined as part of the CORS specification, standardised by the W3C starting around 2014.

Did you know?

Setting it to a literal wildcard * is only allowed for requests without credentials - the moment cookies or Authorization are involved, the spec forces the server to echo back one specific, validated origin instead.