Blog

Kong Gateway: configuring the CORS plugin safely at scale

Use workspaces, plugin ordering, and consumer-scoped overrides without opening a public relay.

1 min read
kongapi-gatewaycors

Plugin precedence

Order matters when CORS runs alongside JWT, ACL, and request-transformer plugins—document the chain.

Use declarative config in Git with review to prevent accidental permissive changes.

Multi-environment drift

Diff staging versus production CORS lists in CI to catch missing partner origins before release.

Automate smoke tests that send Origin headers from each integrated web app.

← Back to blog