Decloak is an AI-powered web security intelligence platform that scans a site's HTTP/TLS posture, JavaScript, and third-party scripts to produce a report anyone can read. This guide is part of Decloak's library of practical, source-backed security guidance.
In this guide
- Key takeaways
- What is the Access-Control-Allow-Origin header?
- How does the header control access?
- What does `*` mean and when can it be used?
- What does a specific origin value mean?
- Why should `null` be avoided?
- Comparison of common values
- How to implement the header safely
- How does this relate to overall web security?
- Frequently asked follow - up questions
- TL;DR
Key takeaways
- The header is part of CORS and controls which origins can read a response.
*allows any origin but only for requests without credentials.- A specific origin value limits access to that exact origin.
nullis technically allowed but should be avoided.- Browsers enforce the rule based on the request's
Originheader.
What is the Access-Control-Allow-Origin header?
The Access-Control-Allow-Origin header is a CORS response header that tells the browser whether the response may be shared with client - side code running on a given origin. It is sent by the server after receiving a cross - origin request that includes an Origin request header.
How does the header control access?
When a browser makes a cross - origin request it includes the Origin header, for example Origin: https://app.example.com. The server examines that value and decides whether to allow it. If it chooses to allow the request, it returns Access-Control-Allow-Origin with either * or the exact origin value. The browser then permits or blocks JavaScript from reading the response based on that header.
What does * mean and when can it be used?
* means any origin may read the response, but only for requests that do not include credentials (cookies, HTTP authentication, or client certificates). If a request includes credentials, the browser will reject a response that uses * and will require a specific origin value.
What does a specific origin value mean?
A specific origin value, such as Access-Control-Allow-Origin: https://example.com, restricts access to scripts that were loaded from exactly that origin. The browser will compare the request's Origin header to the value and allow the response only if they match byte - for - byte.
Why should null be avoided?
The header can also be set to null, which tells the browser to allow any origin that presents a null origin. Because a malicious page can spoof a null origin, using this value effectively opens the resource to anyone and defeats the purpose of CORS.
Comparison of common values
| Header value | Allows any origin? | Allows credentials? | Recommended use |
|---|---|---|---|
* | Yes | No | Public resources that never need cookies or auth |
https://example.com | No | Yes (if Access-Control-Allow-Credentials: true is also set) | Private APIs that serve a single trusted front - end |
null | Technically yes | No | Rare cases like sandboxed iframes; generally avoid |
How to implement the header safely
- Identify which origins need to call the API or load the resource.
- If only one origin is required, configure the server to echo back the exact
Originheader value when it matches the whitelist. - Do not use
*for endpoints that rely on cookies or other credentials. - Avoid
nullunless you have a very specific sandbox use case. - Test with a browser console: make a fetch request from a different origin and verify the response includes the expected header.
How does this relate to overall web security?
Access-Control-Allow-Origin is a first line of defense against cross - site data leakage. It does not replace authentication or authorization checks, but it prevents a malicious site from reading data that the browser would otherwise make available to JavaScript.
Frequently asked follow - up questions
Can I list multiple origins in a single header? No. The specification only allows a single origin value or *. To support multiple origins you must dynamically set the header based on the incoming request.
What happens if the header is missing? The browser treats the response as same - origin only, so any cross - origin script will be blocked from reading the data.
Does the header affect non - browser clients? No. Tools like curl or Postman ignore CORS headers; they are purely a browser enforcement mechanism.
TL;DR
Access-Control-Allow-Origin tells browsers which origins may read a response. Use * only for public, credential - free resources, set a specific origin for protected APIs, and avoid null to keep your data safe.
Related guides
How to Fix a Missing Content - Security - Policy Header
Learn concrete steps to add, test, and harden a Content - Security - Policy header, from server configuration to iterative reporting and verification.
Is HTTP 1.1 a security risk?
HTTP 1.1 is not a direct vulnerability, but its plain - text design and parsing ambiguities can create attack surfaces that need mitigation, especially when not used over TLS.
Is JavaScript a security risk?
JavaScript can be a major attack surface because injected scripts run with the same privileges as the page, but proper sanitization, CSP, and safe frameworks eliminate most risks.