Back to Guides
Guide5 October 2026

How can I remove CORS restrictions?

Decloak is an AI-powered web security intelligence platform that scans a site's HTTP/TLS posture, JavaScript, and third-party scripts to produce a report anyone can read. This guide is part of Decloak's library of practical, source-backed security guidance.

In this guide
  1. Why can’t I simply remove CORS?
  2. Which method lets me satisfy CORS when I control the server?
  3. What if I don’t own the remote API?
  4. Are there browser - only shortcuts for development?
  5. When would JSONP or script - tag tricks help?
  6. Bottom line

How can I remove CORS restrictions?

Key takeaways

Why can’t I simply remove CORS?

CORS is a browser - enforced security feature defined in the web standard, so it cannot be turned off from a web page. The browser blocks any cross - origin request unless the response includes the appropriate Access-Control-Allow-Origin header.

Which method lets me satisfy CORS when I control the server?

Add the correct CORS headers on the server response. For public data you can use Access-Control-Allow-Origin: *; for credentialed requests you must specify the exact origin and include Access-Control-Allow-Credentials: true.

HTTP/1.1 200 OK
Access-Control-Allow-Origin: https://myapp.example
Access-Control-Allow-Credentials: true
Content-Type: application/json

Steps

  1. Open the server configuration (e.g., Express, Nginx, Apache).
  2. Insert the header lines shown above.
  3. Restart the server and verify with the browser console.

What if I don’t own the remote API?

Use a same - origin proxy that you control. The browser sees the request as same - origin, the proxy forwards it to the target, and adds permissive CORS headers to the response.

Example proxy with Node Express

const express = require('express');
const request = require('request');
const app = express();

app.use('/proxy', (req, res) => {
 const url = req.query.url;
 request({ url, json: true }, (err, resp, body) => {
 if (err) return res.status(502).send('Bad gateway');
 res.set('Access-Control-Allow-Origin', '*');
 res.json(body);
 });
});

app.listen(3000, () => console.log('Proxy running on http://localhost:3000'));

Considerations

Are there browser - only shortcuts for development?

Yes, you can launch Chrome or Edge with the flag --disable-web-security or install a CORS - unblock extension. This disables the same - origin policy for that browser instance only.

chrome --disable-web-security --user-data-dir=/tmp/chrome-dev

Limitations

When would JSONP or script - tag tricks help?

Older sites sometimes expose data via a <script> tag, which the browser loads without CORS checks. This works only for GET requests that return JavaScript - compatible payloads.

Example

<script src="https://example.com/data.js"></script>

Risks

Bottom line

You cannot remove CORS; you must either configure the server to send proper headers, route the request through a same - origin proxy, or use insecure developer - only browser flags for local testing. Choose the approach that matches your control over the resource and your security requirements.

Free security scan

See what's actually exposed on your site.

Decloak's free scan runs in about 15 seconds, no account required, and covers:

  • HTTP/TLS security posture
  • JavaScript CVEs
  • Exposed Supabase/Lovable/Base44 misconfigurations
  • AI-written executive summary