Fixing CORS errors in JanitorAI and other browser clients
A CORS error means a web page in your browser tried to call the API directly and the browser blocked it. The API does not answer cross-origin browser requests.
What it looks like
There is no API error message here, because the browser stops the request first. You see something like this in the browser console (F12):
Access to fetch at 'https://wildwestapi.com/v1/chat/completions' from origin 'https://example-chat-site.com' has been blocked by CORS policy: Response to preflight request doesn't pass access control check: No 'Access-Control-Allow-Origin' header is present on the requested resource.
The site itself often just says "Network error", "Failed to fetch" or shows nothing.
Why it happens
Before a page on another site can send a JSON POST with an Authorization header, the browser sends an OPTIONS preflight asking for permission. The API does not answer CORS: an OPTIONS request to /v1/chat/completions gets the generic 404 No route for OPTIONS /v1/chat/completions with no Access-Control-Allow-Origin header, so the browser refuses to send the real request.
Any front end that calls a custom API straight from the browser tab, which is how JanitorAI-style "use your own API" settings and many web chat UIs work, runs into this.
Why SillyTavern works
SillyTavern runs a small server on your machine. The browser talks to that local server, and the server calls the API. Server-to-server requests are not subject to CORS, so there is nothing to block. The same goes for SDK code, scripts, bots and desktop apps.
For reference, the working SillyTavern setup is: API set to Chat Completion, source set to Custom (OpenAI-compatible), endpoint https://wildwestapi.com/v1, your sk-ww- key in the API key field, and a model id such as outlaw-1. The full walkthrough is on the SillyTavern setup page.
What to do
- Use a client that calls the API from a server or a desktop app: SillyTavern, your own backend, a Discord bot, or SDK code.
- If you build a web app, call the API from your backend and have the page talk to your backend. This also keeps your API key out of the page source, where anyone could read it.
- Do not paste a key into a website that will put it in browser requests; even if CORS allowed it, the key would be visible to that page.
Telling it apart from similar errors
If you see an actual HTTP status and JSON body, it is not CORS. A 404 No route for POST from a server-side client is a wrong base URL. A 401 means the request got through but the key is wrong; see 401.
FAQ
Can I fix it with a browser extension that disables CORS?
It may make requests go through on your own machine, but it weakens browser security for every site and exposes your key to the page. A local client like SillyTavern is the safer route.
Does this mean the API is down?
No. The browser blocked the call before it was sent. The same request from curl or SillyTavern works.