Glossary Term
Origin (Scheme, Host, Port)
An origin is the scheme, host and port of a URL. See how browsers compare origins for the same-origin policy, CORS and the Origin header, with examples.
TL;DR: An origin is
scheme + host + port. The browser compares origins to decide what one page may read from another, and sends theOriginheader so servers can do the same.
An origin is the tuple of scheme, host and port taken from a URL. Browsers use it as the unit of trust for the same-origin policy: script running on one origin may send requests to another origin, but may not read the response unless that origin opts in through CORS.
Comparing origins
Against https://app.example.com (port 443 implied):
| URL | Same origin? | Why |
|---|---|---|
https://app.example.com/other/page | Yes | Path is not part of an origin |
https://app.example.com:443/ | Yes | 443 is the default for https |
http://app.example.com/ | No | Scheme differs |
https://api.example.com/ | No | Host differs |
https://app.example.com:8443/ | No | Port differs |
What it looks like on the wire
A cross-origin fetch from https://app.example.com sends:
GET /v1/orders HTTP/1.1
Host: api.example.com
Origin: https://app.example.com
The server answers with Access-Control-Allow-Origin: https://app.example.com or the browser blocks script access to the response. The Origin value has no path and no trailing slash.
Things that trip people up
localhost:3000andlocalhost:8080are different origins. This is the usual cause of a CORS error in local development.- Origin is not site.
app.example.comandapi.example.comare cross-origin but same-site. CORS follows origin;SameSitecookies follow site. See Same-Site vs Same-Origin. - “Origin server” is a different use of the word. In RFC 9110 it means the server that holds the authoritative copy of a resource, as opposed to a proxy or cache.
Originis not sent on every request. Browsers send it on cross-origin requests and on same-origin requests that are not GET or HEAD, so its absence on a plain same-origin GET is normal.
Go deeper
Frequently asked questions
What is an origin in HTTP and the browser?
An origin is the combination of a URL scheme, host and port. Two URLs are same-origin only if all three match exactly.
Is http://example.com the same origin as https://example.com?
No. The scheme differs, so they are different origins, and the default ports (80 and 443) differ as well.
Is a subdomain the same origin?
No. app.example.com and api.example.com are different origins because the host differs, even though they are same-site.
What does Origin: null mean?
The browser is hiding or has no meaningful origin, for example for a sandboxed iframe, a file: page or some cross-origin redirects. Never treat null as trusted in a CORS allowlist.
Sources
Related
Same-Site vs Same-Origin
Site and origin are not the same. Learn how eTLD+1 and the Public Suffix List define same-site, and why it decides SameSite cookie and CORS behavior.
Cross-Origin Resource Sharing (CORS)
Master Cross-Origin Resource Sharing (CORS) for secure cross-origin HTTP requests. Learn preflight requests, headers, credentials, and common error solutions.
Origin Header
Learn how the Origin header identifies where cross-origin requests come from. Essential for CORS security policies and preventing cross-site request forgery.
Access-Control-Allow-Origin Header: CORS Errors and Fixes
Access-Control-Allow-Origin explained: exact browser errors, why * fails with credentials, why you need Vary: Origin, and fixes for nginx, Express and Django.