# Access to fetch has been blocked by CORS policy How to fix it.

URL: https://antideploy.com/blog/cors-error-after-deploy

The browser blocked a request from your frontend to your API. The API must allow your frontend's exact address.

**What you see (in the browser console)**

```
Access to fetch at 'https://my-api.antideploy.app/items' from origin
'https://my-app.antideploy.app' has been blocked by CORS policy: No
'Access-Control-Allow-Origin' header is present on the requested resource.
```

## At a glance

- **What it means**: The API did not allow this origin
- **Fix one**: Allow your live address
- **Fix two**: Not a wildcard
- **Or**: Serve both from one address

Published 7 October 2026. Facts checked 7 October 2026. 1 min read.

## What it means

A browser lets a page call only its own address, unless the other server says the page's origin is allowed. That permission is CORS. Your API did not allow the origin of your frontend, so the browser stopped the call. This is the browser protecting people, and the server decides what to allow.

## How to fix it

### 1. Allow your frontend's exact origin on the API

An origin is the address without a path, for example `https://my-app.antideploy.app`. Add it to the API's allowed origins. Add your own domain too, if you attach one.

### 2. Do not use a wildcard for a private API

`Access-Control-Allow-Origin: *` lets any website call it. Antideploy's security check reports a wide-open CORS policy as a finding.

### 3. Stop using localhost in the frontend

Your frontend must call the live API address. Read it from an environment variable, or use a relative path when both are on one address.

**Express**

```
import cors from "cors";

app.use(cors({ origin: process.env.FRONTEND_ORIGIN }));
```

## The simplest layout

If one server serves both your frontend and your API, they share one origin, and no CORS setup is needed. See [how to deploy a full-stack app](https://antideploy.com/blog/how-to-deploy-a-full-stack-app).

## CORS questions, answered.

Anything else? Write to us and a person answers.

[support@antideploy.com](mailto:support@antideploy.com)

### Why did it work locally?

Locally both sides may be on the same address, or the allowed origin was `localhost`.

### Is CORS a security feature of my API?

It protects visitors' browsers. It does not protect your API from other programs, so protect private data with a sign-in as well.

### Does this failed request cost anything?

No. CORS errors happen in the browser, and a deploy is not involved.

## More guides, and the platform.

Each platform page covers one part of Antideploy: what it does, where it stops and the questions people ask. [See the whole platform](https://antideploy.com/platform), or [all the guides](https://antideploy.com/blog).

- [How to deploy a full-stack app](https://antideploy.com/blog/how-to-deploy-a-full-stack-app): A frontend, an API and a database. One app or two, and what to do about each piece.
- [How to deploy a Vite React app](https://antideploy.com/blog/how-to-deploy-a-vite-react-app): A Vite app deploys as a free static site. The build, the dist folder, routing and variables.
- [Why does my app work on localhost but not online?](https://antideploy.com/blog/why-does-my-app-work-on-localhost-but-not-online): Nine common reasons, how to check each one, and how to fix it.

- [Environment variables](https://antideploy.com/platform/environment-variables)
- [Security checks](https://antideploy.com/platform/security-checks)
- [Deployments](https://antideploy.com/platform/deployments)

Facts on this page were checked against the live platform on 7 October 2026.

## Deploy something. Start with one sentence.

Paste one sentence into your coding agent, click Approve once, and get a live link. No card, no trial clock.

To set this up, give your coding agent this sentence:

```text
Set this project up to deploy on Antideploy. Fetch https://antideploy.com/agent.md and follow it.
```
