ASP.NET Core: The CORS protocol does not allow specifying a wildcard (any) origin and credentials at the same time
The CORS policy uses AllowAnyOrigin() together with AllowCredentials(), which browsers forbid.
Seen on:
.NET
Meaning
With cookies/credentials the server must echo a specific origin. List allowed origins (WithOrigins) or use SetIsOriginAllowed for dynamic checks.
Common causes
- AllowAnyOrigin + AllowCredentials in the same policy
- Copy-paste of permissive dev CORS config
⚡ Quick fix
- Replace AllowAnyOrigin with WithOrigins("https://app.example.com")
- Use SetIsOriginAllowed(origin => …) for validated dynamic origins
Detailed fix by platform
C#
- csharp
builder.Services.AddCors(o => o.AddPolicy("web", p => p .WithOrigins("https://app.example.com") .AllowAnyHeader().AllowAnyMethod().AllowCredentials()));
How to diagnose
- Policy — Origin and credential settings
- Clients — Which origins need cookies?
🔧 Still not fixed?
Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:
Similar errors
- An unhandled error has occurred Blazor: An unhandled error has occurred. Reload 🗙
- antiforgery token could not be decrypted ASP.NET Core: The antiforgery token could not be decrypted / The required antiforgery cookie is not present (400 Bad Request)
- CORS CORS Error: No 'Access-Control-Allow-Origin' header is present
Most viewed in .NET
- NullReferenceException System.NullReferenceException: Object reference not set to an instance of an object
- FileNotFoundException assembly Could not load file or assembly 'X, Version=…' or one of its dependencies
- InvalidOperationException InvalidOperationException: Unable to resolve service for type 'X' while attempting to activate 'Y'
Other ways to find it
🧠 Still stuck? Analyze your error
Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.
Was this page helpful?
Report a correction or suggest an improvement
Last updated 7 Oct 2026