You’re reading the English version of this content since no translation exists yet for this locale. Help us translate this article!
Reason: invalid token ‘xyz’ in CORS header ‘Access-Control-Allow-Headers’
What went wrong?
Access-Control-Allow-Headers header is sent by the server in response to a preflight request; it lets the client know which HTTP headers are permitted in CORS requests. If the client user agent finds among the comma-delineated values provided by the header any header name it does not recognize, this error occurs.
This is a problem that most likely can only be fixed on the server side, by modifying the server's configuration to no longer send the invalid or unknown header name with the
Access-Control-Allow-Headers header. It may also be worth checking to ensure that the user agent or HTTP library you're using on the client is up-to-date.