ENFR0.1.0-rc.3

Enable Try it

Let readers call your API from their browser — and nowhere else.


Enable Try it
0:00 / 0:13
specistry.config.ts
environments: {
  sandbox: { label: "Sandbox", baseUrl: "https://sandbox.testinbox.email" },
  production: { baseUrl: "https://api.testinbox.email" },
  local: { baseUrl: "http://localhost:8080" },
},
playground: {
  mode: "browser",
  environments: ["sandbox", "local"],
  timeoutMs: 15000,
},
  • HTTPS is required, except loopback HTTP for local development
  • Credentials live in browser memory only
  • Forbidden headers are blocked; redirects cannot escape the policy
  • Configuring an environment for examples does not approve it for execution

WarningCORS is your API’s decision

Your API must allow the documentation origin. Specistry ships no proxy to work around it.

Edge cases

Plain HTTP to a remote host

Policy rejected
✕ FAILS
specistry.config.ts
staging: { baseUrl: "http://staging.acme.dev" }
✓ FIX
specistry.config.ts
staging: { baseUrl: "https://staging.acme.dev" }

Only loopback may use HTTP.

Request fails in the browser

Network error
✕ FAILS
browser console
blocked by CORS policy
✓ FIX
API response headers
Access-Control-Allow-Origin: https://docs.acme.dev

The API did not allow the docs origin.

Report an issue with this page on GitHub