Configuring CORS for TypeScript HTTP Endpoints

SkillDev tools

Configuring CORS for TypeScript HTTP endpoints. Use when the user asks to enable CORS, allow cross-origin requests, or configure allowed origins for HTTP endpoints.

Available today. Use it from your connected AI after setup.

Add ahel to your AI once: Claude, ChatGPT, Cursor, Claude Code or Codex. Then ask it to use this.

Then ask your AI: use the Configuring CORS for TypeScript HTTP Endpoints skill

What this skill tells your AI

The instructions your AI receives, as published by golemcloud/golem in golem-skills/skills/ts/golem-add-cors-ts/SKILL.md and read by ahel’s review.

Mount-Level CORS

Set cors on the mount options of http.mount(...) to apply allowed origins to all endpoints:

import { z } from 'zod';
import { defineAgent, method, http } from '@golemcloud/golem-ts-sdk';

export const MyAgent = defineAgent({
  name: 'MyAgent',
  id: { name: z.string() },
  http: http.mount('/api/{name}', { cors: ['https://app.example.com'] }),
  methods: {
    getData: method({ input: {}, returns: Data, http: http.get('/data') }),
    // Allows https://app.example.com
  },
});

Endpoint-Level CORS

Pass cors in the endpoint options (the second argument to a verb builder) to add allowed origins for a specific endpoint. Origins are unioned with mount-level CORS:

export const MyAgent = defineAgent({
  name: 'MyAgent',
  id: { name: z.string() },
  http: http.mount('/api/{name}', { cors: ['https://app.example.com'] }),
  methods: {
    getData: method({ input: {}, returns: Data, http: http.get('/data', { cors: ['*'] }) }),
    // Allows BOTH https://app.example.com AND * (all origins)

    getOther: method({ input: {}, returns: Data, http: http.get('/other') }),
    // Inherits mount-level: only https://app.example.com
  },
});

Wildcard

Use '*' to allow all origins:

export const PublicAgent = defineAgent({
  name: 'PublicAgent',
  id: { name: z.string() },
  http: http.mount('/public/{name}', { cors: ['*'] }),
  methods: { /* ... */ },
});

CORS Preflight

Golem automatically handles OPTIONS preflight requests for endpoints that have CORS configured. The preflight response includes Access-Control-Allow-Origin, Access-Control-Allow-Methods, and Access-Control-Allow-Headers headers.

Signals

GitHub stars
2k
Forks
210
Last commit
Sep 2026
Advanced
Item type
skill
Key
golem-add-cors-ts
Source
github.com/golemcloud/golem