Endpoint
Authentication
Requires a Personal API Access Token.Header
Request
Headers
Path Parameters
Request Body
Full JSON Body Example
Request Body Fields
corsSettings Fields
EnumHttpRequestMethod
GET- GET methodPOST- POST methodPUT- PUT methodDELETE- DELETE methodPATCH- PATCH methodOPTIONS- OPTIONS methodHEAD- HEAD methodTRACE- TRACE methodALL- All methods
Note
allowOriginListcan contain"*"to allow all origins, but this cannot be used withallowCredentials: "true"allowHeaderListcan contain"*"to allow all headersallowCredentialsmust be a string ("true"or"false"), not a boolean
Response
Success Response (200 OK)
deploy=true is specified:
Response Fields
Error Response (400 Bad Request)
Error Response (401 Unauthorized)
Error Response (404 Not Found)
cURL Example
Example 1: Enable CORS for All Origins
Example 2: Enable CORS for Specific Origins
Example 3: Save and Deploy
Notes and Warnings
- Wildcard Origin: Using
"*"inallowOriginListallows all origins but cannot be used withallowCredentials: "true" - Credentials: When
allowCredentialsis"true", you must specify exact origins (no wildcard) - Preflight Requests: The
maxAgevalue determines how long browsers cache preflight OPTIONS requests - Headers: Use
["*"]inallowHeaderListto allow all headers, or specify exact header names - Exposed Headers: Headers in
exposeHeaderListare accessible to client-side JavaScript - Deploy: When
deploy=true, the API proxy is automatically deployed to the specified environments after saving
Permissions
User must haveAPI_MANAGEMENT + MANAGE permission in the project.
Related Documentation
- Update Cache Settings - Update cache settings
- Get API Proxy - Get API proxy details

