Skip to content

CORS preflight

OPTIONS
/v1/query
curl --request OPTIONS \
--url https://api.proofql.dev/v1/query \
--header 'Origin: https://shop.example'

Browsers send this before a POST or a GET with custom headers. It runs without authentication but echoes Access-Control-Allow-Origin only when the key it can see — ?key= (what the snippet’s URL carries; browsers strip Authorization from preflights) or, for non-browser clients, the Authorization header — belongs to a project that lists the Origin (secret keys echo any origin). With no resolvable key or an unlisted origin the preflight still succeeds with no allow-origin header, and the browser blocks the real request itself. Not needed for the snippet’s simple GET.

key
string
/^pq_pk_(live|test)_[0-9A-Za-z]{32}$/

A publishable key, as an alternative to the Authorization header on GET (see the publishableKeyQuery security scheme). Not part of the request shape.

Origin
string format: uri

Set by the browser. Required with a publishable key and must be one of the project’s allowed origins (exact scheme, host, and port), else 403 forbidden. Ignored for secret keys (echoed if present).

Example
https://shop.example

Preflight answered. No body.

x-request-id
required
string
>= 1 characters <= 128 characters

This request’s id, on every response. Reuses the caller’s x-request-id when sent (up to 128 chars), else Cloudflare’s ray id, else a fresh UUID. Also inside every error envelope.

Vary
required
string
Allowed value: Origin

Always Origin on /v1/query, so a shared cache never serves one origin’s CORS headers to another.

Access-Control-Allow-Origin
string

The request’s Origin, echoed when a publishable key’s project lists it or when the key is secret. Absent otherwise (the browser then blocks the response).

Access-Control-Allow-Methods
required
string
Allowed value: GET, POST, OPTIONS
Access-Control-Allow-Headers
required
string
Allowed value: Authorization, Cache-Control, Content-Type

Cache-Control so a page can send no-cache to bypass the result cache.

Access-Control-Max-Age
required
string
Allowed value: 600