Flask-CORS

Cross-Origin Resource Sharing (CORS) support for Flask applications

Library
PyPI
v6.0.5
933 stars
MIT License

Repository Health

Pre-computed score based on development activity, maintenance, community, maturity, and trend momentum. How we score it →
48 /100 Fair
Development Activity 12
Maintenance 32
Community 60
Maturity 60
Momentum 28

Technical Analysis

AI-assessed by reading the actual repository — architecture, code quality, innovation, and documentation. How we score it →
80 /100 Excellent
Architecture 78
Code Quality 82
Innovation 70
Learning Curve 88

Flask-CORS is a small Flask extension that adds Cross-Origin Resource Sharing (CORS) headers to your application’s responses, letting browsers make cross-domain AJAX requests to your API. Rather than manually wiring Access-Control-* headers into every view, you attach the CORS extension to your app (or use the @cross_origin decorator on individual routes) and configure allowed origins, methods, headers, and credential behavior once.

It supports per-resource configuration via regular-expression path matching, so a single app can apply different CORS policies to different route groups (e.g. a public /api/v1/* versus an internal /admin/*). It also wraps Flask’s exception handlers so CORS headers are still applied to error responses, and exposes a vary_header and private-network-access support for modern browser CORS preflight behavior.

What You Get

  • A CORS extension class that can be applied app-wide or per-Blueprint via app.route/Blueprint support
  • A @cross_origin decorator for applying CORS rules to individual view functions
  • Per-resource configuration via regex path patterns, each with its own origins/methods/headers/credentials settings
  • Automatic wrapping of Flask’s exception handlers so error responses also carry CORS headers
  • Support for Access-Control-Allow-Private-Network and Vary: Origin for modern browser CORS semantics

Common Use Cases

  • Enabling a Flask REST API to be called from a separately-hosted single-page app (React/Vue) on a different origin
  • Applying different CORS policies to different route groups, e.g. permissive for /api/public/* and locked-down for /api/admin/*
  • Allowing authenticated cross-origin requests (cookies/credentials) from a known set of trusted origins
  • Adding CORS headers to error responses (4xx/5xx) so frontend error handling still works across origins

Under The Hood

Architecture - Flask-CORS splits into three modules: core.py holds pure option-resolution logic (merging app config, constructor kwargs, and per-resource overrides into a frozen _ComputedCorsOptions dataclass, then serializing it into response headers via set_cors_headers), extension.py wires the CORS class into Flask’s after_request hook and wraps handle_exception/handle_user_exception so error responses also get headers, and decorator.py exposes the equivalent @cross_origin per-view API built on the same core primitives. Resource patterns are regexes sorted longest-to-shortest so the most specific path wins when multiple patterns match. Tech Stack - Pure Python (98% of the codebase) with Flask and Werkzeug as the only runtime dependencies (flask>=0.9, Werkzeug>=0.7), plus typing_extensions for Unpack on Python <3.11; packaged with a pyproject.toml/uv-based build, and CI runs against Python 3.9-3.13. Code Quality - Extensive, well-organized test suite (tests/core, tests/decorator, tests/extension, tests/typecheck) covering origin/header/method matching, credentials, private-network headers, vary-header behavior, and exception interception; type hints are used throughout with TypedDict/Unpack for precise kwarg typing, and inline comments explain non-obvious merge-order and regex-matching decisions. API Design - The dual API (extension-style CORS(app) for whole-app defaults, decorator-style @cross_origin() for per-route overrides) covers both common usage patterns with a single, consistent options vocabulary (origins, methods, allow_headers, supports_credentials, etc.), keeping the barrier to a working CORS setup down to one line of code.

Used by 8 apps in this directory

Python
99%
MIT

Agent Lightning

AI Development

18,515

A Microsoft-built training framework that optimizes AI agents with reinforcement learning, automatic prompt optimization, or supervised fine-tuning — with near-zero code changes to your existing agent, in any framework.

View details
85
Repo Health
68
Technical
69
Dependency
Built with
Python 99%
Updated 4 days ago
TypeScript
49%
AGPL 3.0

Banana Slides

AI Design Tools · Productivity

15,667

AI-native PPT generator with Vibe editing, multi-LLM support, and fully editable PPTX export

View details
84
Repo Health
82
Technical
71
Dependency
Built with
TypeScript 49%
Python 46%
Updated 5 days ago
Python
82%
MIT

CertMate

Devops · Security

1,435

Automate SSL certificate lifecycle across any CA, 24+ DNS providers, and every major secret store — with a REST API, web dashboard, and built-in MCP server for AI-driven ops.

View details
83
Repo Health
84
Technical
70
Dependency
Built with
Python 82%
Updated 5 days ago
Python
79%
Apache 2.0

changedetection.io

Monitoring

34,605

Self-hosted website change detection with AI-powered smart alerts, browser automation, price tracking, and 85+ notification channels.

View details
91
Repo Health
80
Technical
68
Dependency
Built with
Python 79%
Updated 1 weeks ago
TypeScript
50%
Other

Dify

AI Development · Design Tools · Developer Tools

157,364

Visual LLM workflow platform with RAG pipelines, agent capabilities, and model management for building production AI applications.

View details
92
Repo Health
85
Technical
66
Dependency
Built with
TypeScript 50%
Python 47%
Updated 4 days ago
Python
58%
MIT

LibrePhotos

File Storage

8,083

Self-hosted photo library with AI-powered face recognition, semantic search, and automatic event albums — no cloud required.

View details
83
Repo Health
78
Technical
65
Dependency
Built with
Python 58%
TypeScript 40%
Updated 5 days ago
Python
67%
AGPL 3.0

MiroFish

AI Agents · AI Development

75,037

A universal swarm intelligence engine that spawns thousands of autonomous AI agents to simulate and predict how real-world events unfold across social, financial, and political domains.

View details
79
Repo Health
65
Technical
79
Dependency
Built with
Python 67%
Vue 33%
Updated 2 weeks ago
Python
58%
Apache 2.0

MLflow

AI Development · Monitoring

28,154

The open source AI engineering platform for debugging, evaluating, monitoring, and optimizing production LLMs and agents at scale.

View details
97
Repo Health
86
Technical
66
Dependency
Built with
Python 58%
TypeScript 33%
Updated 4 days ago

Join founders buildingwith open source

Opinionated takes, migration guides, cost-saving tips, and insights from the open source ecosystem.

Subscribe on Substack
Join 750+ subscribers