Contents

Web & Networking › HTTP

Origin

Scheme + host + port: the browser's security boundary.

Also known as: web origin, same origin, origin header

An origin is the combination of a URL’s scheme, host and port. It’s the unit the browser uses for its security rules.

https://app.example.com:443/path?q=1
└─┬─┘   └──────┬──────┘ └┬┘
scheme       host       port      → origin: https://app.example.com:443

The path and query are not part of the origin. Default ports (443 for https, 80 for http) are implied.

Same origin or not

Compared with https://app.example.com:

URLSame origin?Why
https://app.example.com/otheryesonly the path differs
http://app.example.comnodifferent scheme
https://api.example.comnodifferent host
https://app.example.com:8443nodifferent port

What depends on it

  • The same-origin policy: a page can freely read data only from its own origin.
  • CORS: a server explicitly allows other origins through headers.
  • Storage: localStorage and IndexedDB are separate per origin (localStorage).
  • Cookies use a related but different idea: site and domain rules, not origin (cookies, SameSite).
  • postMessage between windows checks origins.
  • The Origin request header tells a server which origin made a cross-origin request:
Origin: https://app.example.com

Servers use it to decide whether to allow the request, and to defend against forged requests (CSRF).

Practical points

  • localhost:3000 and localhost:8000 are different origins, which is why local frontend and API setups hit CORS errors.
  • Don’t trust the Origin header from non-browser clients. It can be forged. It protects users in browsers.
  • Allow-lists of origins should be exact, not “anything ending with example.com”.
  • Don’t confuse origin with site (the registrable domain, such as example.com), which has a wider scope.