CORS Preflight Failing: The Header Checklist

Symptom

OPTIONS request returns without Access-Control-Allow-Origin; browser blocks the call.

Root cause

The server (or a proxy in front) is not answering the preflight OPTIONS with the right headers.

Fix, in order

1. Test the preflight directlycurl -i -X OPTIONS https://api.example.com/x -H 'Origin: https://app.example.com' -H 'Access-Control-Request-Method: POST'
2. Handle OPTIONS explicitly in your server/routerif (req.method === "OPTIONS") return new Response(null, { headers: corsHeaders })
3. Echo the exact Origin, not *Access-Control-Allow-Origin: https://app.example.com
4. Allow the headers the client actually sendsAccess-Control-Allow-Headers: Content-Type, Authorization

Prevent it coming back

One CORS middleware for every route; integration tests must include OPTIONS.

Run it on clean infra

Spinning up a fresh box to reproduce or escape this error?

Build apps without servers

Related

Cloud & DevOps tool comparisons · Hardware build guides

NinjaOps publishes free engineering guides. Some outbound links are affiliate links: they cost you nothing and support the site.

Last reviewed 2026-10-02 · NinjaOps SEO grid · DevOps blog