CORS for Chrome Extensions: What Actually Works

Chrome extensions live in a weird middle ground. They’re not normal web pages, but they’re not fully trusted native apps either. That matters a lot for CORS. If you build extensions long enough, you hit this fast: fetch() works in your background service worker the same request fails in a content script adding Access-Control-Allow-Origin to your request does nothing people tell you to “just use host_permissions” and then preflights still surprise you The mental model that has saved me the most time is this: ...

October 1, 2026 · 7 min · headertest.com

CORS and Chrome Platform Apps: Practical Reference

Chrome platform apps have always been a weird corner of the web platform. They look like web apps, use web APIs, and make HTTP requests like a browser. But they also run with elevated privileges and their network behavior does not match a normal tab. If you work on CORS-heavy APIs, that difference matters. This guide is the practical version: what changes, what still applies, and what headers you actually need. ...

June 20, 2026 · 7 min · headertest.com