How HTTP Works

Glossary Term

Origin (Scheme, Host, Port)

An origin is the scheme, host and port of a URL. See how browsers compare origins for the same-origin policy, CORS and the Origin header, with examples.

Reviewed 2 min readbeginner3 sourcesMarkdown
On this page

TL;DR: An origin is scheme + host + port. The browser compares origins to decide what one page may read from another, and sends the Origin header so servers can do the same.

An origin is the tuple of scheme, host and port taken from a URL. Browsers use it as the unit of trust for the same-origin policy: script running on one origin may send requests to another origin, but may not read the response unless that origin opts in through CORS.

Comparing origins

Against https://app.example.com (port 443 implied):

URLSame origin?Why
https://app.example.com/other/pageYesPath is not part of an origin
https://app.example.com:443/Yes443 is the default for https
http://app.example.com/NoScheme differs
https://api.example.com/NoHost differs
https://app.example.com:8443/NoPort differs

What it looks like on the wire

A cross-origin fetch from https://app.example.com sends:

GET /v1/orders HTTP/1.1
Host: api.example.com
Origin: https://app.example.com

The server answers with Access-Control-Allow-Origin: https://app.example.com or the browser blocks script access to the response. The Origin value has no path and no trailing slash.

Things that trip people up

  • localhost:3000 and localhost:8080 are different origins. This is the usual cause of a CORS error in local development.
  • Origin is not site. app.example.com and api.example.com are cross-origin but same-site. CORS follows origin; SameSite cookies follow site. See Same-Site vs Same-Origin.
  • “Origin server” is a different use of the word. In RFC 9110 it means the server that holds the authoritative copy of a resource, as opposed to a proxy or cache.
  • Origin is not sent on every request. Browsers send it on cross-origin requests and on same-origin requests that are not GET or HEAD, so its absence on a plain same-origin GET is normal.

Go deeper

Frequently asked questions

What is an origin in HTTP and the browser?

An origin is the combination of a URL scheme, host and port. Two URLs are same-origin only if all three match exactly.

Is http://example.com the same origin as https://example.com?

No. The scheme differs, so they are different origins, and the default ports (80 and 443) differ as well.

Is a subdomain the same origin?

No. app.example.com and api.example.com are different origins because the host differs, even though they are same-site.

What does Origin: null mean?

The browser is hiding or has no meaningful origin, for example for a sandboxed iframe, a file: page or some cross-origin redirects. Never treat null as trusted in a CORS allowlist.

Sources

  1. MDN Web Docs: Origindeveloper.mozilla.org
  2. RFC 6454: The Web Origin Conceptrfc-editor.org
  3. WHATWG HTML Standard: Originhtml.spec.whatwg.org

Keep going

Browse /search