CORS preflight
const url = 'https://api.proofql.dev/v1/query';const options = {method: 'OPTIONS', headers: {Origin: 'https://shop.example'}};
try { const response = await fetch(url, options); const data = await response.json(); console.log(data);} catch (error) { console.error(error);}curl --request OPTIONS \ --url https://api.proofql.dev/v1/query \ --header 'Origin: https://shop.example'Browsers send this before a POST or a GET with custom headers. It
runs without authentication but echoes Access-Control-Allow-Origin
only when the key it can see — ?key= (what the snippet’s URL
carries; browsers strip Authorization from preflights) or, for
non-browser clients, the Authorization header — belongs to a
project that lists the Origin (secret keys echo any origin). With
no resolvable key or an unlisted origin the preflight still succeeds
with no allow-origin header, and the browser blocks the real request
itself. Not needed for the snippet’s simple GET.
Parameters
Section titled “Parameters”Query Parameters
Section titled “Query Parameters”A publishable key, as an alternative to the Authorization
header on GET (see the publishableKeyQuery security scheme). Not
part of the request shape.
Header Parameters
Section titled “Header Parameters”Set by the browser. Required with a publishable key and must be
one of the project’s allowed origins (exact scheme, host, and port),
else 403 forbidden. Ignored for secret keys (echoed if present).
Example
https://shop.exampleResponses
Section titled “Responses”Preflight answered. No body.
Headers
Section titled “Headers”This request’s id, on every response. Reuses the caller’s
x-request-id when sent (up to 128 chars), else Cloudflare’s ray id,
else a fresh UUID. Also inside every error envelope.
Always Origin on /v1/query, so a shared cache never serves one origin’s CORS headers to another.
The request’s Origin, echoed when a publishable key’s project lists
it or when the key is secret. Absent otherwise (the browser then
blocks the response).
Cache-Control so a page can send no-cache to bypass the result cache.