DEV Community

Nadim Chowdhury
Nadim Chowdhury

Posted on

CORS Doesn't Protect Your API. Here's What It Actually Does.

One of the most persistent misconceptions in web development:
'CORS protects our backend API from unauthorized requests.'

It does not.

CORS is a browser-enforced security mechanism designed to protect users, not servers.
If a malicious site tries to make an authenticated fetch request to your banking API using your browser's existing cookies, the browser blocks the response from being read by the malicious origin.

However:

  • curl does not respect CORS
  • Postman does not respect CORS
  • Python scripts do not respect CORS
  • Backend-to-backend calls do not respect CORS

If your API security relies on CORS headers alone without proper token authentication and CSRF defense, your API is completely unprotected.

Test and debug API configurations safely:
https://utilifi.vercel.app

Top comments (0)