Web applications use Cross-Origin Resource Sharing (CORS) to request resources from
origins other than their own. For example, a web page can use CORS to request information about a
user from your My Domain login URL or Experience Cloud site URL. In addition to public and
allowlisted web pages, Salesforce supports CORS for certain OAuth endpoints when requested from a
My Domain login URL or Experience Cloud site URL.
Required Editions
Available in: both Salesforce Classic and
Lightning Experience
Available in: All Editions
User Permissions Needed
To create, read, update, and delete:
Modify All Data AND Customize Application
CORS is automatically enabled for these endpoints.
/.well-known/openid-configuration
/.well-known/auth-configuration
/services/oauth2/id/keys
In addition, you can enable CORS for the /services/oauth2/userinfo endpoint by adding the origin URL of the web application
serving the code to the CORS allowlist.
You can also enable CORS for these endpoints by selecting the Enable CORS for OAuth endpoints
checkbox. Salesforce supports CORS for these endpoints only for certain host domains.
Endpoint
Supported Host Domains for CORS
/services/oauth2/token
My Domain or Experience Cloud site URLs
/services/oauth2/revoke
My Domain or Experience Cloud site URLs
/services/oauth2/introspect
My Domain or Experience Cloud site URLs
services/oauth2/authorize
My Domain or Experience Cloud site URLs
services/oauth2/pkce/generator
My Domain or Experience Cloud site URLs
services/auth/headless/init/registration
Experience Cloud site URLs only
services/auth/headless/init/passwordless/login
Experience Cloud site URLs only
services/auth/headless/forgot_password
Experience Cloud site URLs only
Warning Some OAuth authorization flows contain a consumer secret. We strongly
recommend that you protect the consumer secret from being exposed to end users.
To enable CORS for the endpoints listed in the table, take these steps.
From Setup, in the Quick Find box, enter CORS, and then select
CORS.
Add the origin URL of the web application serving the code to a CORS allowlist.
In the Cross-Origin Resource Sharing (CORS) Policy Settings section, click
Edit.
Select Enable CORS for OAuth endpoints.
Save your work.
Did this article solve your issue?
Let us know so we can improve!
Loading
Salesforce Help | Article
Cookie Consent Manager
General Information
Required Cookies
Functional Cookies
Advertising Cookies
General Information
We use three kinds of cookies on our websites: required, functional, and advertising. You can choose whether functional and advertising cookies apply. Click on the different cookie categories to find out more about each category and to change the default settings.
Privacy Statement
Required Cookies
Always Active
Required cookies are necessary for basic website functionality. Some examples include: session cookies needed to transmit the website, authentication cookies, and security cookies.
Functional Cookies
Functional cookies enhance functions, performance, and services on the website. Some examples include: cookies used to analyze site traffic, cookies used for market research, and cookies used to display advertising that is not directed to a particular individual.
Advertising Cookies
Advertising cookies track activity across websites in order to understand a viewer’s interests, and direct them specific marketing. Some examples include: cookies used for remarketing, or interest-based advertising.