CORS

The API sets Access-Control-Allow-Credentials: true to support cookie-based authentication. Allowed origins are configured via api.cors_origins in the server config. Wildcard origins (*) are not supported (incompatible with credentials).

CORS headers:

Preflight requests: OPTIONS requests return 204 No Content with CORS headers.