BlogBrowser

Access to fetch has been blocked by CORS policy How to fix it.

The browser blocked a request from your frontend to your API. The API must allow your frontend's exact address.

How the Agent API works
What you see (in the browser console)
Access to fetch at 'https://my-api.antideploy.app/items' from origin
'https://my-app.antideploy.app' has been blocked by CORS policy: No
'Access-Control-Allow-Origin' header is present on the requested resource.
  • What it meansThe API did not allow this origin
  • Fix oneAllow your live address
  • Fix twoNot a wildcard
  • OrServe both from one address

What it means

A browser lets a page call only its own address, unless the other server says the page's origin is allowed. That permission is CORS. Your API did not allow the origin of your frontend, so the browser stopped the call. This is the browser protecting people, and the server decides what to allow.

How to fix it

  1. Allow your frontend's exact origin on the API

    An origin is the address without a path, for example https://my-app.antideploy.app. Add it to the API's allowed origins. Add your own domain too, if you attach one.

  2. Do not use a wildcard for a private API

    Access-Control-Allow-Origin: * lets any website call it. Antideploy's security check reports a wide-open CORS policy as a finding.

  3. Stop using localhost in the frontend

    Your frontend must call the live API address. Read it from an environment variable, or use a relative path when both are on one address.

Express
import cors from "cors";

app.use(cors({ origin: process.env.FRONTEND_ORIGIN }));

The simplest layout

If one server serves both your frontend and your API, they share one origin, and no CORS setup is needed. See how to deploy a full-stack app.

01Questions

CORS questions, answered.

Anything else? Write to us and a person answers.

support@antideploy.com
Why did it work locally?

Locally both sides may be on the same address, or the allowed origin was localhost.

Is CORS a security feature of my API?

It protects visitors' browsers. It does not protect your API from other programs, so protect private data with a sign-in as well.

Does this failed request cost anything?

No. CORS errors happen in the browser, and a deploy is not involved.

Deploy something. Start with one sentence.

Paste one sentence into your coding agent, click Approve once, and get a live link. No card, no trial clock.

Start from GitHub or a folder
Prompt copied Paste it into Claude Code, Codex or Cursor and press Enter.