CORS
The API sets Access-Control-Allow-Credentials: true to support cookie-based authentication. Allowed origins are configured via api.cors_origins in the server config. Wildcard origins (*) are not supported (incompatible with credentials).
CORS headers:
Access-Control-Allow-Origin: {origin} (echoed from request if allowed)
Access-Control-Allow-Methods: GET, POST, PUT, DELETE, OPTIONS
Access-Control-Allow-Headers: Content-Type, Authorization, X-API-Key
Access-Control-Allow-Credentials: true
Access-Control-Max-Age: 3600
Preflight requests: OPTIONS requests return 204 No Content with CORS headers.