Generate CORS headers for Nginx or Apache

Turn your allowed origin, methods, and headers into copy-ready server config and a matching fetch().

By The DevFixPro Editorial Team · independent editorial research project

Private by design. Every tool linked below runs 100% in your browser — your code, text, and tokens never leave your device.

You know the fix, not the syntax

You have diagnosed a CORS error and know which origin and methods to allow — but you do not remember the exact Nginx add_header block or the Apache mod_headers syntax, and you keep getting the credentials rule wrong.

Generate it

Open the CORS Header Generator: enter the Allow-Origin, toggle methods, list Allow-Headers, set Max-Age, and choose credentials. It emits a Nginx block, an Apache block, and a matching fetch() example you can paste straight in.

Worked example

Origin https://app.example.com, methods GET/POST, headers Content-Type, Authorization, Max-Age 600, credentials off → a clean Nginx location /api/ block with an OPTIONS → 204 preflight handler.

Boundaries

  • If Allow-Credentials is on, the generator keeps Allow-Origin as your exact origin (not *), which the spec requires.
  • The snippet is a starting point — adapt to your server version and existing config.

FAQ

Why the OPTIONS handler? Browsers send a preflight OPTIONS request for non-simple requests; it must return 204 with the CORS headers.

Still blocked after deploying? Re-run the CORS Diagnostic with the new console error.

Frequently Asked Questions

Why can I not combine a wildcard origin with credentials?

Because allowing any origin to send authenticated requests would defeat the same origin policy entirely. The server has to echo the specific requesting origin instead, which is the header combination the generator produces.

What is a preflight request for?

Before a request that could have side effects, the browser asks permission for the method and headers it intends to use. The server has to answer that exchange correctly or the real request is never sent.

The API works in a tool but fails in the browser. Which side is broken?

Neither, usually. The tool is not bound by the browser rules, so the endpoint is fine and the response headers are the missing piece. That is the fastest way to separate a header problem from a server problem.

← All guides

Related tools from our network

A focused set of free calculators and guides across related topics — no account required.