CORS in Go: Fixing Gin and Echo in Production

I’ve seen a lot of Go APIs ship with one of two CORS setups: AllowOrigins: ["*"] and a prayer no CORS config at all, followed by frontend people yelling in Slack Both work fine right up until browsers get involved. This case study is based on a pretty typical setup: a Go backend serving JSON to a separate frontend app, first on localhost, then across staging and production domains. The backend started on Gin, another service used Echo, and both had the same problem: “it works in curl” but fails in the browser. ...

September 12, 2026 · 6 min · headertest.com