Glossary · Network and discovery

Cross-Origin Resource Sharing (CORS)

The browser protocol that lets a server allow web pages from other origins to read its responses, using Access-Control headers and preflight requests.

Cross-Origin Resource Sharing (CORS) is the protocol, defined in the WHATWG Fetch Standard, by which a server tells browsers whether pages from other origins may read its responses.

How it works. A server opts in by returning Access-Control-Allow-Origin with either the requesting origin or *. For requests beyond what an HTML form can send, such as a JSON POST with custom headers, the browser first sends a preflight: an OPTIONS request carrying Access-Control-Request-Method and, where needed, Access-Control-Request-Headers. The browser sends the real request only if the preflight response allows that method and those headers.

A real preflight. This is a request to Emissar’s public A2A endpoint and its response, captured on 26 September 2026 and trimmed to the CORS headers:

OPTIONS /a2a/v1 HTTP/1.1
Host: emissar.ai
Origin: https://example.com
Access-Control-Request-Method: POST
Access-Control-Request-Headers: content-type, a2a-version

HTTP/1.1 204 No Content
Access-Control-Allow-Origin: *
Access-Control-Allow-Headers: Content-Type, A2A-Version, A2A-Extensions, Authorization
Access-Control-Allow-Methods: POST, GET, OPTIONS
Access-Control-Max-Age: 86400

The endpoint is public and unauthenticated, so any origin may call it. Access-Control-Max-Age asks the browser to cache the allowed methods and headers for 86,400 seconds; the Fetch Standard lets a browser impose a lower limit, and uses 5 seconds when the header is absent.

Credentials and wildcards. When a request’s credentials mode is “include”, for example to send cookies, Access-Control-Allow-Origin cannot be *. The server must return the exact origin and Access-Control-Allow-Credentials: true, and the wildcard also stops working for the allowed methods and headers. The Fetch Standard calls Access-Control-Allow-Origin: * safe for any resource that anyone could already fetch with tools like curl, and unsafe for resources protected only by IP address or a firewall.

What CORS does not do. It decides what a browser lets a page read. It does not authenticate callers and does not bind clients outside a browser. An agent calling an A2A endpoint from a server never sends a preflight, so authentication, authorization and rate limiting still have to happen on the endpoint itself.

Neighbouring terms. Server-side request forgery is the server-side risk that comes with fetching URLs on someone else’s behalf. The Agent Card at a well-known URI is often fetched cross-origin by browser-based tools.

Sources

  1. WHATWG Fetch Standard, section 3.3: CORS protocol (accessed )
  2. Emissar A2A endpoint preflight response (captured 2026-09-26) (accessed )