Skip to content
Shrake DevTools
  • JSON FormatterData & Format
  • JSON ValidatorData & Format
  • JSON MinifierData & Format
  • JSON ↔ YAML ConverterData & Format
  • XML FormatterData & Format
  • Base64 Encoder / DecoderData & Format
  • URL Encoder / DecoderData & Format
  • JWT InspectorData & Format
↑ ↓ to navigate↵ to openEsc to close

CORS Header Generator

Runs locally in your browser. Your input is not uploaded.Free, no sign-up

Allowed origins

One per line. Use https://*.example.com for subdomains.

Methods

Headers

Spring MVC

Generate CORS configuration for Spring Boot, Nginx, Express and Apache.

How to use the CORS Header Generator

  1. List the origins (scheme, host and port) your frontend runs on, and pick the methods and headers it uses.
  2. Decide whether requests carry cookies or an Authorization header (credentials).
  3. Copy the configuration for your stack, or the raw headers to check a response against.

How CORS works

Browsers block JavaScript from reading responses from another origin unless the server allows it. For anything beyond a simple GET or form POST, the browser first sends a preflight OPTIONS request asking which methods and headers are allowed, and only then the real request.

  • Access-Control-Allow-Origin must be the exact origin (or * without credentials). Servers that allow several origins echo the request's Origin back when it's on their list, and add Vary: Origin so caches don't mix them up.
  • Access-Control-Allow-Credentials: true lets cookies and auth headers through; it never works with *.
  • Access-Control-Max-Age caches the preflight answer, saving a round trip on every request.

Frequently asked questions

Why do I still get CORS errors with Spring Security?

The security filter may reject the preflight (no credentials) with 401 before your CORS configuration runs. Define a CorsConfigurationSource bean and call http.cors(Customizer.withDefaults()), as the Spring Security output shows.

Is CORS a security feature for my API?

It protects users' browsers, not your server: curl and other servers ignore it. Keep authentication and authorization on every endpoint.