What is CORS and why do API calls fail in the browser?
PICTURE THIS: BROWSER VS ATTACKER
Simple meaning
Browsers block a page on one origin from reading responses from another origin unless the server sends Access-Control-Allow-Origin.
WHY — Browser instead of guessing?
Why interviewers care about Browser:
who only read docs from people who shipped.
and tied to Frontend work.
Name the idea, why it exists, then one short example.
End with when you use it and one common pitfall.
STEPS — What happens step by step?
Before you speak the answer, walk the interviewer through these steps:
- 1Browsers block a page
on one origin from reading responses from another origin unless the server sends Access-Control-Allow-Origin.
- 2The API can still
work in Postman because that tool is not a browser.
- 3The fix is server
headers or a same-origin proxy, not a frontend hack.
- 4Give an example
One tiny concrete case you can say aloud.
- 5Common mistake
What juniors usually get wrong.
- 6Close
When you pick this over the alternative.
EXAMPLE — See it in action
Here's a short line you can speak, broken into clear beats:
Note: Adapt this scaffold to your own project — keep it under 60–90 seconds.
Key takeaway
Browsers block a page on one origin from reading responses from another origin unless the server sends Access-Control-Allow-Origin. The API can still work in Postman because that tool is not a browser.