Last active December 6, 2022 21:28
.htaccess to add CORS to your website
# Add these three lines to CORSify your server for everyone.
Header set Access-Control-Allow-Origin "*"
Header set Access-Control-Allow-Methods "GET,PUT,POST,DELETE"
Header set Access-Control-Allow-Headers "Content-Type, Authorization"

CORSify a folder in Apache

Add the above three lines to an .htaccess file to enable CORS for that folder and its subfolders. Of course, you could also add this to the httpd.conf file if you have access.


  • Ensure that the mod_headers Apache Module is enabled.
  • This will open things up pretty grandly. This may or may not be what you want.


  • Do at your own risk, etc. etc.
  • My Apache-fu is weak, so there may well be a better solution.
If this problem can't be solved by .htaccess, then try to put in your PHP file next: header("Access-Control-Allow-Origin: *");

I don't understand. Which PHP file?

