# Origin (Scheme, Host, Port)

> An origin is the scheme, host and port of a URL. See how browsers compare origins for the same-origin policy, CORS and the Origin header, with examples.

Source: https://howhttpworks.com/glossary/origin
Last reviewed: 2026-10-04

> **TL;DR:** An origin is `scheme + host + port`. The browser compares origins to decide what one page may read from another, and sends the `Origin` header so servers can do the same.

An origin is the tuple of scheme, host and port taken from a URL. Browsers use it as the unit of trust for the same-origin policy: script running on one origin may send requests to another origin, but may not read the response unless that origin opts in through CORS.

## Comparing origins

Against `https://app.example.com` (port 443 implied):

| URL | Same origin? | Why |
| --- | --- | --- |
| `https://app.example.com/other/page` | Yes | Path is not part of an origin |
| `https://app.example.com:443/` | Yes | 443 is the default for https |
| `http://app.example.com/` | No | Scheme differs |
| `https://api.example.com/` | No | Host differs |
| `https://app.example.com:8443/` | No | Port differs |

## What it looks like on the wire

A cross-origin `fetch` from `https://app.example.com` sends:

```http
GET /v1/orders HTTP/1.1
Host: api.example.com
Origin: https://app.example.com
```

The server answers with `Access-Control-Allow-Origin: https://app.example.com` or the browser blocks script access to the response. The `Origin` value has no path and no trailing slash.

## Things that trip people up

- **`localhost:3000` and `localhost:8080` are different origins.** This is the usual cause of a CORS error in local development.
- **Origin is not site.** `app.example.com` and `api.example.com` are cross-origin but same-site. CORS follows origin; `SameSite` cookies follow site. See [Same-Site vs Same-Origin](https://howhttpworks.com/glossary/same-site).
- **"Origin server" is a different use of the word.** In RFC 9110 it means the server that holds the authoritative copy of a resource, as opposed to a proxy or cache.
- **`Origin` is not sent on every request.** Browsers send it on cross-origin requests and on same-origin requests that are not GET or HEAD, so its absence on a plain same-origin GET is normal.

## Go deeper

- [Origin header](https://howhttpworks.com/headers/origin)
- [Access-Control-Allow-Origin](https://howhttpworks.com/headers/access-control-allow-origin)
- [CORS guide](https://howhttpworks.com/guides/cors)
- [CORS error: no Access-Control-Allow-Origin header](https://howhttpworks.com/debug/cors-no-access-control-allow-origin)
