How to disable CORS in Firefox

In Chrome you can start the browser with web security switched off. Firefox has no such switch — and the about:config setting most answers point to does the opposite of what you want. Here's what actually works when you need to test against an API that doesn't send CORS headers yet.

On this page
  1. The about:config trap
  2. Allow CORS for one site with an add-on
  3. A dev-server proxy
  4. Local files (file://)
  5. The real fix

The about:config trap

Search for "disable CORS Firefox" and you'll be told to set content.cors.disable to true. Don't. That preference turns cross-origin requests off entirely: every one of them then fails, and the console says Reason: CORS disabled. It exists for locking Firefox down, not for opening it up. If you already changed it, set it back to false.

Firefox has no supported equivalent of Chrome's --disable-web-security, and that's deliberate: switching off the same-origin policy for a whole browser lets any page read your data from any site you're signed in to.

Allow CORS for one site with an add-on

The narrow way is to add the missing Access-Control-Allow-* headers to responses from just the API you're testing. Every other site keeps normal protection. Two limits apply to any tool that does this: it can't turn a preflight the server rejects (401, 404, 405…) into a success, and it only changes your browser.

CORS Unblock — HeaderForge (Firefox, free)

Allow CORS for one site with one switch, then turn it off again when you're done. It also sets or removes any request or response header, blocks or redirects requests, and shows whether each rule fired. No account, no tracking, nothing sent anywhere.

The Firefox version is in review at Firefox Add-ons; a link will appear here once Mozilla approves it.

Get it for Chrome

A dev-server proxy

Route API calls through your own dev server, so the browser only ever talks to one origin and CORS never comes up:

// vite.config.js
export default {
  server: { proxy: { "/api": "http://localhost:8080" } }
};

Then call fetch("/api/users") instead of the full URL.

Local files (file://)

If the problem is an HTML file opened straight from disk that can't load other local files, that's a different rule. security.fileuri.strict_origin_policy relaxes it, but it weakens protection for every HTML file you open. Better: serve the folder with a local server, for example python3 -m http.server, and open http://localhost:8000.

The real fix

Everything above only helps you. For your users the server has to send the headers — CORS error: what it means and how to fix it has the code, and the CORS tester shows what a request actually gets back. Using Chrome? See how to disable CORS in Chrome.

More on this topic: TypeError: Failed to fetch — what it actually means, and how to tell which cause · net::ERR_BLOCKED_BY_CLIENT, ERR_BLOCKED_BY_RESPONSE and ERR_BLOCKED_BY_ORB · “Has been blocked by CORS policy”: every variant and its fix · Access-Control-Allow-Origin: values, multiple origins and server examples