--- layout: default ---

Access-Control-Allow-Origin

IANA permanent response reached by regulation

Declared by 30 providers across 3087 published specification files in the APIs.io network.

What this header is for, and how to use it →

A count here is providers whose published contract declares this header — not providers who send it. Response headers set at the edge rarely appear in an OpenAPI at all, so a low number can measure documentation practice rather than deployment.

Reached by regulation

Basis: evidentiary. No law names this header; it is the deployed control for an obligation that regulation does impose. Observable at the edge, without credentials.

gdpr dora

The registry

Statuspermanent
ReferenceFetch

Providers declaring it (30)

aerin-medical aimlapi bird braintrust brightcove coveo deliverect echo-global genius-sports koko kore-wireless lichess micro1 newstore ordoro palo-alto-networks payerset placer planomy-tax-data qualio receeve rhumbix roadsync ron-swanson-quotes salesforce shyft tealium tricentis vtex waodao

Explore

All headers CORS Guidance on headers.apievangelist.com