CORS: "credentials mode is include" — The Three-Header Rule

Symptom

Fetch with cookies blocked: "credentials mode is include" errors in console.

Root cause

Cookie-bearing CORS needs exact header alignment, and * is banned.

Fix, in order

1. Explicit origin + credentials headerAccess-Control-Allow-Origin: https://app.example.com Access-Control-Allow-Credentials: true
2. The fetch must ask for themfetch(url, { credentials: 'include' })
3. Cross-site cookies need SameSite=None; SecureSet-Cookie: session=x; SameSite=None; Secure; HttpOnly

Prevent it coming back

Cookie CORS is a contract of three headers; test all three in CI.

Run it on clean infra

Spinning up a fresh box to reproduce or escape this error?

Build apps without servers

Related

Cloud & DevOps tool comparisons · Hardware build guides

NinjaOps publishes free engineering guides. Some outbound links are affiliate links: they cost you nothing and support the site.

Last reviewed 2026-10-02 · NinjaOps SEO grid · DevOps blog