Docs CORS & domain allowlist
Docs
CORS & domain allowlist
If your form submits directly from a visitor's browser, the browser enforces CORS (Cross-Origin Resource Sharing) — it will only let your page's JavaScript read the response from a request to another domain if that domain says it's allowed to. The domain allowlist is how you tell PostTo which of your domains to say yes to.
The default: wide open
By default an endpoint's domain allowlist is empty, and PostTo allows requests from any origin. This is deliberate — a plain
<form action="..."> submission needs no special CORS handling to work at all, and most PostTo forms are simple HTML with
nothing else to protect. If your form does a JavaScript fetch() and reads the JSON response, it'll work from any domain out of the
box.
Restricting it
Add one or more domains under an endpoint's Settings → Domain allowlist to restrict which sites may successfully call it from a browser. Once
set, a browser request from a domain not on the list gets rejected with origin_not_allowed (403) — and the browser blocks the
JavaScript from reading the response either way, since PostTo won't send the matching CORS header.
Origin header — a header only
browsers send automatically and honestly. Any non-browser client (a server, a script, curl, Postman) can set Origin to whatever it
wants, or omit it entirely, in which case the allowlist isn't checked at all. Real authentication is the token in your endpoint URL, plus the
HMAC signature if you're using signed mode. Treat the allowlist as a CORS convenience for
browsers, not a security boundary.
Server-to-server requests
Requests from your own backend — including all signed-mode requests — typically don't send
an Origin header at all, so the domain allowlist has no effect on them regardless of what's configured. It only ever applies to
requests a browser makes on a page's behalf.
Try it against your own form
Create an endpoint and get a working URL in under a minute — free plan, no credit card.
Start for free