CORS config generator
Generate a CORS setup: fill in the allowed origins, methods and headers, credentials and preflight cache time to get the full response header list (with an explanation for each header) plus copy-pasteable snippets for nginx, Express, FastAPI, Spring and Caddy — including warnings about pitfalls such as wildcard origins with credentials. Configuration only, no requests are made.
Runs in your browserEvery computation happens in your browser — your data never leaves this device.
CORS rules
Everything is generated locally by self-written rules: no requests are sent and your server is never probed — the output is just configuration and code snippets.
Result
Fill in the origins and methods, then press Generate config.
What this tool does
- First integration of a decoupled front end and API fails with “No Access-Control-Allow-Origin header is present” — list every header that should be sent and copy it into your backend.
- Give teammates on different stacks the same policy: keep one set of origins, methods and headers and switch between the nginx, Express, FastAPI, Spring or Caddy snippets instead of hand-writing each.
- Debug “cross-origin request with cookies fails”: the tool warns that `*` and credentials are mutually exclusive, and that you must echo the Origin together with Vary: Origin.
- Pre-launch review: confirm you opened only the methods and headers you need instead of blanket-allowing sensitive headers such as Authorization.
Example
Input
Origin https://app.example.com; methods GET, POST, OPTIONS; allowed headers Content-Type, Authorization; exposed header X-Total-Count; credentials on; preflight cache 600 s; path /api/
Output
Access-Control-Allow-Origin: https://app.example.com; Access-Control-Allow-Methods: GET, POST, OPTIONS; Access-Control-Allow-Headers: Content-Type, Authorization; Access-Control-Expose-Headers: X-Total-Count; Access-Control-Allow-Credentials: true; Access-Control-Max-Age: 600; Vary: Origin (7 headers in total, plus an Express snippet with `origin: 'https://app.example.com', … credentials: true, maxAge: 600`)
Changing the origin to `*` fails immediately: wildcard origins cannot be combined with credentials, a hard rule of the fetch standard.
Frequently asked questions
Why can’t `*` be used together with credentials?
The fetch standard says that when a request carries credentials (cookies, Authorization), `Access-Control-Allow-Origin` must name a concrete origin rather than `*`, or the browser rejects the response outright. The reason is that `*` would expose credential-bearing responses to any site. This tool blocks that combination before generating anything.
What does Vary: Origin actually fix?
If you echo the request’s Origin into `Access-Control-Allow-Origin`, the same URL returns different headers to different origins. A cache (CDN, reverse proxy, browser cache) that does not know this can hand site A’s response to site B, breaking CORS or leaking data. `Vary: Origin` tells them the response depends on the Origin.
What should Access-Control-Max-Age be?
It is how many seconds the browser may cache the preflight result, and browsers cap it (usually 600 s for Chrome, 86400 for Firefox). 600–3600 is a common choice: it removes a lot of OPTIONS requests while a policy change still takes effect within that window. Setting 0 omits the header, so every call is preflighted again.
Why must custom request headers be listed explicitly?
Only safelisted request headers (Accept, Accept-Language, Content-Language and some Content-Type values) can be sent without a preflight. Authorization, X-Api-Key, X-Requested-With and friends all trigger a preflight, and the server has to list them in `Access-Control-Allow-Headers` — otherwise the preflight response does not cover them and the real request is never sent.
Does the tool change my server configuration?
No. It only produces the header list and snippets; it sends no requests and never probes your server, so applying the change is up to you. To verify what production actually returns, run `curl -i -X OPTIONS -H "Origin: https://app.example.com" -H "Access-Control-Request-Method: POST" https://your-api/...`.
Keywords:corsaccess-control-allow-originpreflightnginx corsexpress corsfastapi corsCORS 配置跨域预检请求跨域请求头通配符来源凭证