Fetch with cookies blocked: "credentials mode is include" errors in console.
Cookie-bearing CORS needs exact header alignment, and * is banned.
Access-Control-Allow-Origin: https://app.example.com
Access-Control-Allow-Credentials: truefetch(url, { credentials: 'include' })Set-Cookie: session=x; SameSite=None; Secure; HttpOnlyCookie CORS is a contract of three headers; test all three in CI.
Spinning up a fresh box to reproduce or escape this error?
Build apps without serversNinjaOps publishes free engineering guides. Some outbound links are affiliate links: they cost you nothing and support the site.
Last reviewed 2026-10-02 · NinjaOps SEO grid · DevOps blog