Cross-Origin Sharing

Allowed Origins: origins permitted to access the resource

Allowed Methods: HTTP methods allowed

Allowed Headers: lists headers that can be used

Supports Credentials: if response can be exposed with credentials

Exposed Headers: headers safe to expose to the API

Max Age: length of a preflight request cache