# CORS & Security Headers — Fastify

Source: https://www.geekswithgeeks.com/en/fastify/ff-cors

> Control cross-origin requests and response headers safely.

## CORS (Cross-Origin Resource Sharing)

Browsers block cross-origin requests by default. CORS headers tell browsers which origins are allowed to call your API.

## Configuring CORS

Use @fastify/cors to control allowed origins, methods, and headers.

```javascript
import cors from '@fastify/cors';

await fastify.register(cors, {
  origin: ['https://myapp.com', 'http://localhost:3001'],
  methods: ['GET', 'POST', 'PUT', 'DELETE'],
  credentials: true,
});
```
