{"id":8822,"date":"2026-05-29T16:18:28","date_gmt":"2026-05-29T14:18:28","guid":{"rendered":"https:\/\/mybox.com\/help\/?post_type=manual_kb&#038;p=8822"},"modified":"2026-06-09T21:03:29","modified_gmt":"2026-06-09T19:03:29","slug":"what-is-cors-and-how-does-it-work","status":"publish","type":"manual_kb","link":"https:\/\/mybox.com\/help\/en\/knowledgebase\/what-is-cors-and-how-does-it-work\/","title":{"rendered":"What Is CORS?"},"content":{"rendered":"\n<div class=\"translation-block translation-block-merged\">\n<p class=\"wp-block-paragraph\">CORS (Cross-Origin Resource Sharing) is a browser security mechanism that controls how web pages can access resources hosted on different websites or domains.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">It allows servers to specify which external websites are permitted to request their resources. This helps protect users and applications from unauthorized access while still enabling legitimate communication between different services.<\/p>\n\n\n\n<\/div>\n\n<div id=\"mybox-271312218\" class=\"mybox-content mybox-entity-placement\"><div class=\"early-access-banner-inpost\">\r\n  <div class=\"banner-left-inpost\">\r\n    <div class=\"icon-box-inpost\">\r\n      <img decoding=\"async\" src=\"https:\/\/mybox.com\/help\/wp-content\/uploads\/2026\/02\/square-info-icon.svg\" alt=\"Info\">\r\n    <\/div>\r\n    <div class=\"text-box-inpost\">\r\n      <span class=\"label-inpost\"><span class=\"translation-block translation-block-banner-text\">Early access<\/span><\/span>\r\n      <h4><span class=\"translation-block translation-block-banner-text\">Still need help?<\/span><\/h4>\r\n      <p><span class=\"translation-block translation-block-banner-text\">Contact our customer service team.<\/span><\/p>\r\n    <\/div>\r\n  <\/div>\r\n\r\n  <div class=\"banner-right-inpost\">\r\n    <a href=\"https:\/\/panel.mybox.com\/helpdesk2\/v\/list\/\" class=\"banner-button-inpost\"><span class=\"translation-block translation-block-banner-text\">Message us<\/span><\/a>\r\n  <\/div>\r\n<\/div><\/div>\n\n<div class=\"translation-block translation-block-merged\"><p class=\"wp-block-paragraph\">CORS is commonly used when websites interact with APIs, external services, or resources hosted on separate domains.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<div id=\"ez-toc-container\" class=\"ez-toc-v2_0_86 ez-toc-wrap-left counter-hierarchy ez-toc-counter ez-toc-custom ez-toc-container-direction\">\n<div class=\"ez-toc-title-container\">\n<p class=\"ez-toc-title\" style=\"cursor:inherit\">Table of Contents<\/p>\n<span class=\"ez-toc-title-toggle\"><\/span><\/div>\n<nav><ul class='ez-toc-list ez-toc-list-level-1 ' ><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-1\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/what-is-cors-and-how-does-it-work\/#What_Is_an_Origin\" >What Is an Origin?<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-2\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/what-is-cors-and-how-does-it-work\/#Why_CORS_Exists\" >Why CORS Exists<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-3\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/what-is-cors-and-how-does-it-work\/#How_CORS_Works\" >How CORS Works<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-4\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/what-is-cors-and-how-does-it-work\/#Simple_and_Preflight_Requests\" >Simple and Preflight Requests<\/a><ul class='ez-toc-list-level-3' ><li class='ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-5\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/what-is-cors-and-how-does-it-work\/#Simple_Requests\" >Simple Requests<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-6\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/what-is-cors-and-how-does-it-work\/#Preflight_Requests\" >Preflight Requests<\/a><\/li><\/ul><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-7\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/what-is-cors-and-how-does-it-work\/#Same-Origin_Policy_vs_CORS\" >Same-Origin Policy vs. CORS<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-8\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/what-is-cors-and-how-does-it-work\/#Common_Use_Cases\" >Common Use Cases<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-9\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/what-is-cors-and-how-does-it-work\/#Practical_Implications\" >Practical Implications<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-10\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/what-is-cors-and-how-does-it-work\/#Summary\" >Summary<\/a><\/li><\/ul><\/nav><\/div>\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"What_Is_an_Origin\"><\/span>What Is an Origin?<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Before understanding CORS, it is important to understand the concept of an <strong>origin<\/strong>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">An origin is defined by three elements:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Protocol (HTTP or HTTPS)<\/li>\n\n\n\n<li>Domain name<\/li>\n\n\n\n<li>Port number<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">For example:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>https:&#47;&#47;example.com\n<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">and<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>https:&#47;&#47;api.example.com\n<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">are considered different origins because they use different domains.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Why_CORS_Exists\"><\/span>Why CORS Exists<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Modern browsers follow a security model known as the <strong>Same-Origin Policy<\/strong>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">By default, a webpage can only access resources from the same origin that served the page.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Without this restriction, a malicious website could potentially access sensitive information from other websites that a user is logged into.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">CORS provides a controlled way for servers to relax this restriction when cross-origin access is required.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"How_CORS_Works\"><\/span>How CORS Works<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">When a webpage attempts to access a resource from a different origin, the browser sends a request to the target server.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The server can respond with specific HTTP headers that indicate whether the request should be allowed.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">One of the most common headers is:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>Access-Control-Allow-Origin\n<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">This header tells the browser which origins are permitted to access the resource.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If the server allows the requesting origin, the browser grants access to the response. If not, the browser blocks access and reports a CORS error.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Simple_and_Preflight_Requests\"><\/span>Simple and Preflight Requests<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">CORS requests are generally divided into two categories.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Simple_Requests\"><\/span>Simple Requests<span class=\"ez-toc-section-end\"><\/span><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Simple requests use standard HTTP methods such as:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>GET<\/li>\n\n\n\n<li>HEAD<\/li>\n\n\n\n<li>POST<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">For these requests, the browser sends the request directly and then checks whether the server permits access.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Preflight_Requests\"><\/span>Preflight Requests<span class=\"ez-toc-section-end\"><\/span><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Some requests require additional verification before they are sent.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In these cases, the browser first sends a preliminary request known as a <strong>preflight request<\/strong> using the HTTP <code>OPTIONS<\/code> method.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The server responds with information about:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Allowed origins<\/li>\n\n\n\n<li>Allowed HTTP methods<\/li>\n\n\n\n<li>Allowed headers<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Only if the response permits the operation will the browser send the actual request.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Same-Origin_Policy_vs_CORS\"><\/span>Same-Origin Policy vs. CORS<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Same-Origin Policy \u2260 CORS<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">These concepts work together but serve different purposes.<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th>Same-Origin Policy<\/th><th>CORS<\/th><\/tr><\/thead><tbody><tr><td>Browser security restriction<\/td><td>Permission mechanism<\/td><\/tr><tr><td>Blocks cross-origin access by default<\/td><td>Allows approved cross-origin access<\/td><\/tr><tr><td>Applied automatically by browsers<\/td><td>Configured by the server<\/td><\/tr><tr><td>Protects users from unauthorized access<\/td><td>Enables secure communication between services<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">CORS does not replace the Same-Origin Policy. It provides controlled exceptions to it.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Common_Use_Cases\"><\/span>Common Use Cases<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">CORS is commonly used for:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>API integrations<\/li>\n\n\n\n<li>Single-page applications (SPAs)<\/li>\n\n\n\n<li>External authentication services<\/li>\n\n\n\n<li>Payment gateways<\/li>\n\n\n\n<li>Content delivery networks (CDNs)<\/li>\n\n\n\n<li>Third-party integrations<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Many modern web applications rely on CORS to communicate with external services.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Practical_Implications\"><\/span>Practical Implications<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">CORS is primarily a browser security feature.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A CORS error does not necessarily mean the server is unavailable. In many cases, it means the server has not explicitly allowed the requesting origin.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Website owners and developers may encounter CORS-related issues when connecting applications to APIs or external services. Resolving these issues typically involves adjusting the server&#8217;s CORS configuration.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Summary\"><\/span>Summary<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">CORS (Cross-Origin Resource Sharing) is a browser security mechanism that allows servers to control which external websites can access their resources. It works alongside the Same-Origin Policy to enable secure communication between different web applications, APIs, and services while helping protect users from unauthorized access.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n<\/div>\n","protected":false},"author":1,"featured_media":0,"parent":0,"menu_order":0,"template":"","format":"standard","manualknowledgebasecat":[10,42],"manual_kb_tag":[6576,1292,6568,6569,6570,6571,6572,6573,6574,6575],"class_list":["post-8822","manual_kb","type-manual_kb","status-publish","format-standard","hentry","manualknowledgebasecat-safety","manualknowledgebasecat-miscellaneous","manual_kb_tag-single-page-applications","manual_kb_tag-server-configuration","manual_kb_tag-cross-origin-resource-sharing","manual_kb_tag-cors","manual_kb_tag-same-origin-policy","manual_kb_tag-browser-security","manual_kb_tag-access-control-allow-origin-header","manual_kb_tag-preflight-request","manual_kb_tag-simple-requests","manual_kb_tag-http-methods"],"_links":{"self":[{"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/manual_kb\/8822","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/manual_kb"}],"about":[{"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/types\/manual_kb"}],"author":[{"embeddable":true,"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/users\/1"}],"version-history":[{"count":2,"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/manual_kb\/8822\/revisions"}],"predecessor-version":[{"id":8823,"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/manual_kb\/8822\/revisions\/8823"}],"wp:attachment":[{"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/media?parent=8822"}],"wp:term":[{"taxonomy":"manualknowledgebasecat","embeddable":true,"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/manualknowledgebasecat?post=8822"},{"taxonomy":"manual_kb_tag","embeddable":true,"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/manual_kb_tag?post=8822"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}