NG-Anti-CORS is a powerful browser extension that enables Cross-Origin Resource Sharing with a single click – perfect for testing APIs and debugging web apps in local environments. 🔧
- Easy to Use 🖱️ – One-click activation for any domain
- Domain-specific Control 🌐 – Enable CORS per-site
- Advanced Fetch & XHR Support 🔄 – Deep integration with browser request APIs
- Preflight Control 🛂 – Optional handling of CORS preflight (
OPTIONS) requests - All HTTP Methods 📡 – Basic mode supports GET, POST, HEAD and PUT; Advanced mode unlocks PATCH, DELETE, OPTIONS and the rest
- Visual Indicators 💡 – Color-coded icons show current status
- Save Settings 💾 – Keep your preferences after browser restarts
- Customizable Notifications 🔔 – Decide how and when toast notifications appear
- Supports Requests with Credentials* 🔑 – Cookies / auth headers pass through if the target server sends
Access-Control-Allow-Credentials: true - Lightweight 🪶 – Pure Declarative Net Request, zero remote calls, minimal overhead
* Browsers require the target API to set Access-Control-Allow-Credentials: true; NG-Anti-CORS never injects that header automatically.
- Open the Chrome / Edge / Opera listing
- Click Add to Chrome and confirm
- Download the latest release .zip
- Unzip to any folder
- Open
chrome://extensions/(oredge://extensions/) - Enable Developer mode (top right)
- Click Load unpacked and select the unzipped folder
Opera users: Install the helper extension “Install Chrome Extensions” first, then follow the Chrome steps.
- Open a page that shows CORS errors
- Click the NG-Anti-CORS icon
- Toggle Enable CORS for the current domain
- (Optional) Toggle Preflight Request handling for advanced scenarios
- (Optional) Check Remember this setting to persist across restarts
- Reload the page – CORS restrictions are gone!
When NG-Anti-CORS is disabled for a domain, it leaves the browser’s security model untouched.
| Mode | Enabled HTTP methods | Typical use-case |
|---|---|---|
| Basic (default) | GET, POST, PUT, HEAD | Simple REST calls, most front-end dev work |
| Advanced (Preflight) | Full method set: PATCH, DELETE, OPTIONS … | APIs needing custom headers, credentials, complex verbs |
Enable Preflight Request handling when:
- You call APIs with PATCH, DELETE, OPTIONS, etc.
- Your requests include custom headers (e.g.
Authorization,X-Auth-Token) - You see “Method not allowed” or failed preflight in DevTools
- You need to send cookies or HTTP-auth cross-origin and the server supports it
- Click the NG-Anti-CORS icon
- Open the Settings tab
- Change notification duration, default toggles, …
- Click Save
Ideal for:
- Front-end devs consuming third-party APIs
- Testing local micro-services (e.g.
localhost:3000↔︎localhost:5000) - Debugging CORS errors in staging / prod
- Rapid API prototyping with tools like Postman, Swagger UI, etc.
- Verify the extension is active (green icon)
- Check that CORS is enabled for the current domain
- Hard-reload the page (Ctrl + F5)
- Inspect DevTools → Network for failing requests
- Confirm the target server actually blocks CORS – some errors originate elsewhere
- No telemetry – zero personal data collected
- No remote servers – all logic runs locally via the Chrome Declarative Net Request API; no proxying
- Minimal storage – only remembers your per-domain toggles
Security notice: Use NG-Anti-CORS only in development or on trusted sites. Turning off CORS weakens standard browser protections.
- Fixed stray notifications on untouched domains
- Exempted Google / YouTube CORS flow from modification
- Smarter detection of existing CORS headers
- Only shows notifications when relevant and respecting user settings
- Improved handling of protected Chrome/Edge pages
- Switched header ops from APPEND → SET to avoid duplicates
- Unique DNR rule IDs to bypass extension conflicts
- Performance tweaks: skip domains that don’t need CORS fixes
(Older logs: see CHANGELOG.md)
- Fork →
git checkout -b feature/AmazingFeature - Commit →
git commit -m "feat: add AmazingFeature" - Push →
git push origin feature/AmazingFeature - Open a Pull Request – we ❤️ PRs!
MIT – see LICENSE.
Developed with ❤️ for the web-dev community.