Cross Origin Resource Sharing (CORS)
Published: Jan 10, 2015   -   Updated: Dec 21, 2017

What is CORS?

Cross-origin resource sharing (CORS) is a standard browser feature that allows JavaScript hosted on your websites to make an XMLHttpRequest (XHR) to the Okta API with the Okta session cookie.

Caution: Only grant access to specific websites that you control and trust to access the Okta API

Specifying Websites

To specify CORS settings:

  1. on the Okta Dashboard, navigate to Security > API
  2. Click Add Origin
  3. Enter the website name and URL with which you want to share resources
  4. check the CORS checkbox
  5. Select Save.




