How AI is applied across API Evangelist and APIs.io. Read my AI disclosure →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

Origin

CORS IANA permanent request 2 spellings

A reference entry. The registry facts and catalog measurements below are complete; the written guidance for this header has not been authored yet.

The Origin HTTP header — cors, RFC 6454, declared by 14 providers in the API Evangelist catalog.

Origin is cors — The cross-origin negotiation. A small, closed set of headers that decide whether a browser is allowed to see a response it already received.

The registry

Listed in the IANA HTTP Field Name Registry as a permanent entry. Defined in RFC 6454: The Web Origin Concept.

In the catalog

Declared by 14 providers across 124 published specification files in the API Evangelist catalog, where it appears as a request header — sent by the client.

It is spelled 2 different ways across those contracts — Origin, origin. HTTP field names are case-insensitive (RFC 9110, §5.1), so every one of these is the same header. They are not the same string, which is why generated clients disagree about it.

Governed by these rules

Machine-enforceable governance rules from rules.apievangelist.com that apply to this header when it appears in an OpenAPI.

OpenAPI Components Headers Error error

Utilizing the headers object in the centralized OpenAPI components library helps make headers reusable across API requests and responses

Guidance: Rate Limits →
OpenAPI Components Headers Info info

Utilizing the headers object in the centralized OpenAPI components library helps make headers reusable across API requests and responses

Guidance: Rate Limits →
OpenAPI Headers Hyphenated Pascal Case error

HTTP headers should follow Hyphenated-Pascal-Case naming convention for consistency and readability, such as Content-Type, X-Request-Id, or Accept-Language.

Guidance: Naming →
OWASP API8 2023 Define CORS Origin error

Setting up CORS headers will control which websites can make browser-based HTTP requests to your API. The Access-Control-Allow-Origin header should be defined on all responses.

Guidance: Security →