In Chrome you can start the browser with web security switched off. Firefox has no such switch — and the about:config setting most answers point to does the opposite of what you want. Here's what actually works when you need to test against an API that doesn't send CORS headers yet.
Search for "disable CORS Firefox" and you'll be told to set content.cors.disable to true. Don't. That preference turns cross-origin requests off entirely: every one of them then fails, and the console says Reason: CORS disabled. It exists for locking Firefox down, not for opening it up. If you already changed it, set it back to false.
Firefox has no supported equivalent of Chrome's --disable-web-security, and that's deliberate: switching off the same-origin policy for a whole browser lets any page read your data from any site you're signed in to.
The narrow way is to add the missing Access-Control-Allow-* headers to responses from just the API you're testing. Every other site keeps normal protection. Two limits apply to any tool that does this: it can't turn a preflight the server rejects (401, 404, 405…) into a success, and it only changes your browser.
Allow CORS for one site with one switch, then turn it off again when you're done. It also sets or removes any request or response header, blocks or redirects requests, and shows whether each rule fired. No account, no tracking, nothing sent anywhere.
The Firefox version is in review at Firefox Add-ons; a link will appear here once Mozilla approves it.
Get it for ChromeRoute API calls through your own dev server, so the browser only ever talks to one origin and CORS never comes up:
// vite.config.js
export default {
server: { proxy: { "/api": "http://localhost:8080" } }
};
Then call fetch("/api/users") instead of the full URL.
If the problem is an HTML file opened straight from disk that can't load other local files, that's a different rule. security.fileuri.strict_origin_policy relaxes it, but it weakens protection for every HTML file you open. Better: serve the folder with a local server, for example python3 -m http.server, and open http://localhost:8000.
Everything above only helps you. For your users the server has to send the headers — CORS error: what it means and how to fix it has the code, and the CORS tester shows what a request actually gets back. Using Chrome? See how to disable CORS in Chrome.
More on this topic: TypeError: Failed to fetch — what it actually means, and how to tell which cause · net::ERR_BLOCKED_BY_CLIENT, ERR_BLOCKED_BY_RESPONSE and ERR_BLOCKED_BY_ORB · “Has been blocked by CORS policy”: every variant and its fix · Access-Control-Allow-Origin: values, multiple origins and server examples