Firefox Tomorrow

http header

Access-Control-Allow-Methods header

View on MDN ↗

The HTTP Access-Control-Allow-Methods response header specifies one or more HTTP request methods allowed when accessing a resource in response to a preflight request.

Header type [Response header](https://developer.mozilla.org/en-US/docs/Glossary/Response%20header)

Syntax

Access-Control-Allow-Methods: <method>, <method>, …
Access-Control-Allow-Methods: *

Directives

  • <method>
    • : A comma-separated list of the allowed request methods. GET, HEAD, and POST are always allowed, regardless of whether they are specified in this header, as they are defined as CORS-safelisted methods.
  • * (wildcard)
    • : All HTTP methods. It has this meaning only for requests without credentials (requests without HTTP cookies or HTTP authentication information). In requests with credentials, it is treated as the literal method name * without special semantics.

Examples

Access-Control-Allow-Methods: PUT, DELETE
Access-Control-Allow-Methods: *

Specifications

SpecificationsStandards references are available on the canonical MDN page.

Browser compatibility

Browser compatibilityCompatibility data is available on the canonical MDN page.

See also