Skip to content

Errors / Blocked by the browser

Response to preflight request doesn't pass access control check

Before sending its real request, the browser asked the other server for permission, and did not get it.

The real request is never sent.

Why it happens

  • A request with a JSON body, an Authorization header or a method other than GET/POST makes the browser send an OPTIONS request first.
  • The server does not answer OPTIONS (404, 405, or a redirect), or answers without Access-Control-Allow-Methods / Access-Control-Allow-Headers for what the page sends.
  • Access-Control-Allow-Origin: * together with credentials (cookies), which browsers refuse.

How to fix it

  1. Make the server answer OPTIONS with 204 and the Access-Control-Allow-Origin, -Methods and -Headers the real request needs.
  2. With cookies, name the origin exactly and add Access-Control-Allow-Credentials: true.
  3. Never redirect a preflight: fix the URL (trailing slash, http→https) instead.

Whose problem it is

Usually the server that answers the request.

Does your site have it?

Free, no account. We open your page and four more in a clean Chrome and list every error like this one, with the page and the click that caused it. How the free page check works.

Check only sites you run or have permission to check.

Often seen with

  • Blocked by CORS policyThe page asked another website for data, and that website did not say this page may read it.