OPTIONS request returns without Access-Control-Allow-Origin; browser blocks the call.
The server (or a proxy in front) is not answering the preflight OPTIONS with the right headers.
curl -i -X OPTIONS https://api.example.com/x -H 'Origin: https://app.example.com' -H 'Access-Control-Request-Method: POST'if (req.method === "OPTIONS") return new Response(null, { headers: corsHeaders })Access-Control-Allow-Origin: https://app.example.comAccess-Control-Allow-Headers: Content-Type, AuthorizationOne CORS middleware for every route; integration tests must include OPTIONS.
Spinning up a fresh box to reproduce or escape this error?
Build apps without serversNinjaOps publishes free engineering guides. Some outbound links are affiliate links: they cost you nothing and support the site.
Last reviewed 2026-10-02 · NinjaOps SEO grid · DevOps blog