---
name: azion-enable-cors-on-an-application
description: >-
  Add Response Phase rules that send CORS headers for GET, POST, and HEAD requests, for complex requests, or for a list of allowed origins.
---

# Enable CORS on an application

You can enable Cross-Origin Resource Sharing (CORS) on an [application](/en/documentation/platform/applications/) from Azion Console, with Response Phase rules in [Rules Engine for Applications](/en/documentation/platform/applications/rules-engine/). Each section creates one rule that adds CORS headers to the responses of the application.

CORS uses HTTP headers to grant a user agent access to resources on an origin server other than the current document's. For example, an HTML page served by domain A requests a CSS stylesheet or a JavaScript file from domain B. For security reasons, most browsers block the cross-origin HTTP requests that scripts start. The CORS headers in a response tell the browser which of these requests to allow.

A request that uses `GET`, `POST`, or `HEAD` needs only the `Access-Control-Allow-Origin` header in the response. Any other request can be considered complex. So can a request that involves multiple parameters, headers, authentication, a request body, or another specialized configuration. A complex request needs additional headers.

---

## Prerequisites

- An application that a [workload](/en/documentation/platform/workloads/) delivers, with a rule that sends its requests to an origin. To create both, refer to [Applications quickstart](/en/documentation/platform/applications/quickstart/).
- Access to Azion Console. To sign in, refer to [Access Azion Console](/en/documentation/guides/platform/account-and-billing/how-to-access-azion-console/).

---

## Allow cross-origin GET, POST, and HEAD requests

The rule in this section adds `Access-Control-Allow-Origin: *` to the responses of every path that starts with `/your-uri`. The `*` value lets a page from any origin read those responses. Replace `/your-uri` with the path that receives the cross-origin requests.

To create the rule in Azion Console:

1. **Open the application**

   Access [Azion Console](https://console.azion.com/) > **Applications** > **your application**.

2. **Select the Rules Engine tab**

3. **Select + Rule**

4. **Name the rule**

   In the **General** section, enter `GET/POST/HEAD CORS` in **Name**.

5. **(Optional) Describe the rule**

   In **Description**, enter `Allows CORS for GET requests in /your-uri`.

6. **Select Response Phase**

   In the **Phase** section, select **Response Phase**. The phase of a rule cannot change after you create the rule.

7. **Set the criterion**

   In the **Criteria** section, select `${uri}` as the variable and `starts_with` as the operator.

8. **Enter the path**

   Enter `/your-uri` as the argument.

9. **Add the header behavior**

   In the **Behaviors** section, select the behavior that adds a response header. The API names it `add_response_header`.

10. **Enter the header**

    Enter `Access-Control-Allow-Origin: *` as the argument of the behavior.

11. **Select Save**

The rule appears in the **Rules Engine** tab, under **Response**. The responses to paths that start with `/your-uri` carry `Access-Control-Allow-Origin: *`. For the format that a header argument takes, refer to [Add Request Header](/en/documentation/platform/applications/rules-engine/#add-request-header).

---

## Allow complex cross-origin requests

A complex request needs more headers than `Access-Control-Allow-Origin`. The rule in this section allows the `OPTIONS` method on paths that start with `/your-uri`. Its headers also cover `GET`, `POST`, and `HEAD` requests to those paths. The rule adds these five headers to each response:

```text
Access-Control-Allow-Origin: *
Access-Control-Allow-Headers: Content-Type, Authorization
Access-Control-Request-Method: POST, GET, OPTIONS, HEAD
Allow: POST, GET, OPTIONS, HEAD
Access-Control-Allow-Methods: POST, GET, OPTIONS, HEAD
```

To create the rule in Azion Console:

1. **Open the application**

   Access [Azion Console](https://console.azion.com/) > **Applications** > **your application**.

2. **Select the Rules Engine tab**

3. **Select + Rule**

4. **Name the rule**

   In the **General** section, enter `OPTIONS CORS` in **Name**.

5. **(Optional) Describe the rule**

   In **Description**, enter `Allows CORS for OPTIONS requests in /your-uri, as well as non-complex requests`.

6. **Select Response Phase**

   In the **Phase** section, select **Response Phase**. The phase of a rule cannot change after you create the rule.

7. **Set the criterion**

   In the **Criteria** section, select `${uri}` as the variable and `starts_with` as the operator.

8. **Enter the path**

   Enter `/your-uri` as the argument.

9. **Add the header behavior**

   In the **Behaviors** section, select the behavior that adds a response header. The API names it `add_response_header`.

10. **Enter the first header**

    Enter `Access-Control-Allow-Origin: *` as the argument of the behavior.

11. **Add the other four headers**

    For each remaining header in the list, select **+ Add Behavior**. Select the same behavior, and enter the header as its argument.

12. **Select Save**

The rule appears in the **Rules Engine** tab, under **Response**. The responses to paths that start with `/your-uri` carry the five headers.

To allow other request types, change the values of `Allow`, `Access-Control-Allow-Methods`, and `Access-Control-Allow-Origin`. To set the format of the response, add a `Content-Type` header to the same rule.

---

## Allow cross-origin requests from specific origins

The rule in this section adds the CORS headers only when a request comes from one of three origins. It reads the `Origin` request header through the `${http_origin}` variable, with one criterion per origin, joined by **Or**. Replace the three origins with the ones your application accepts:

```text
http://www.example.com
http://app.example.com
http://example.org
```

A rule that allows specific origins requires [Application Accelerator](/en/documentation/platform/applications/application-accelerator/settings/#module-activation) on the application.

To turn on Application Accelerator in Azion Console:

1. **Open the application**

   Access [Azion Console](https://console.azion.com/) > **Applications** > **your application**.

2. **Select the Main Settings tab**

3. **Turn on Application Accelerator**

   In the **Modules** section, turn on **Application Accelerator**.

4. **Select Save**

The application runs with Application Accelerator on. Turning on a Product can generate usage-related costs. For more information, refer to [Pricing](/en/documentation/fundamentals/pricing/).

The rule adds the same five headers as a rule for complex requests:

```text
Access-Control-Allow-Origin: *
Access-Control-Allow-Headers: Content-Type, Authorization
Access-Control-Request-Method: POST, GET, OPTIONS, HEAD
Allow: POST, GET, OPTIONS, HEAD
Access-Control-Allow-Methods: POST, GET, OPTIONS, HEAD
```

To create the rule in Azion Console:

1. **Open the Rules Engine tab**

   Access [Azion Console](https://console.azion.com/) > **Applications** > **your application**, then select the **Rules Engine** tab.

2. **Select + Rule**

3. **Name the rule**

   In the **General** section, enter `Multiple origins CORS` in **Name**.

4. **Select Response Phase**

   In the **Phase** section, select **Response Phase**. The phase of a rule cannot change after you create the rule.

5. **Set the first criterion**

   In the **Criteria** section, select `${http_origin}` as the variable and `is_equal` as the operator.

6. **Enter the first origin**

   Enter `http://www.example.com` as the argument.

7. **Add the other two origins**

   For each remaining origin, select **Or**. Select `${http_origin}` and `is_equal` again, and enter the origin as the argument.

8. **Add the header behavior**

   In the **Behaviors** section, select the behavior that adds a response header. The API names it `add_response_header`.

9. **Enter the first header**

   Enter `Access-Control-Allow-Origin: *` as the argument of the behavior.

10. **Add the other four headers**

    For each remaining header in the list, select **+ Add Behavior**. Select the same behavior, and enter the header as its argument.

11. **Select Save**

The rule appears in the **Rules Engine** tab, under **Response**. A response carries the five headers only when the `Origin` header of its request matches one of the three origins exactly. For how criteria combine with **And** and **Or**, refer to [Conditionals](/en/documentation/platform/applications/rules-engine/#conditionals).

---

## Next steps

- [Rules Engine for Applications](/en/documentation/platform/applications/rules-engine.md#behaviors): Every behavior an application rule can run, by phase, and the Product each one requires.
- [Create request and response rules](/en/documentation/guides/application-development/getting-started/rules-engine.md): Create rules for the Request Phase and the Response Phase of an application.
- [Application Accelerator settings](/en/documentation/platform/applications/application-accelerator/settings.md): What Application Accelerator adds to an application, and the rules that require it.
- [Debug rules created with Rules Engine](/en/documentation/guides/application-development/getting-started/debug-rules.md): Find out whether a rule ran on a request, through the GraphQL API, Data Stream, or Real-Time Events.
