# Elastic API returns 401 from browser client (CORS)

**URL:** <https://discuss.elastic.co/t/elastic-api-returns-401-from-browser-client-cors/360686>\
**Category:** Elasticsearch\
**Created:** [June 3, 2024, 4:30am UTC](https://discuss.elastic.co/t/elastic-api-returns-401-from-browser-client-cors/360686 "2024-06-03T04:30:46Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![qd-danh](https://avatars.discourse-cdn.com/v4/letter/q/43a26b/32.png) [@qd-danh](https://discuss.elastic.co/u/qd-danh)\
**Post date:** [June 3, 2024, 4:30am UTC](https://discuss.elastic.co/t/elastic-api-returns-401-from-browser-client-cors/360686/1 "2024-06-03T04:30:46Z")

</div>

I have followed the documentation and enabled CORS on Elastic cluster (hosted in Azure), so edited the elastic YAML via the cloud portal. Shown below.

Calling Elastic APIs from ObservableHQ as the client and getting CORS error response. The client has a "no-cors" setting that I can pass, then I get a 401 Unauthorized. I know I have the correct API key and the API works, since I can make the same exact call from POSTMAN and it succeeds.

Calling Elastic API: `GET /my-index/_search`

I realize the ObservableHQ client calls are probably very specific to my case. So more of a general question: do you know if there is anything else I should be having to do other than edit `elastic.yaml` to allow CORS calls?

Following documentation here

> **[Set up CORS for Behavioral Analytics | Elasticsearch Guide \[8.13\] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/behavioral-analytics-cors.html)**

Settings in `elastic.yaml`

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/f/2/f2b2fc53fa5a285a29a8b537f1718f877be953b3.png)

Client call in ObservableHQ, Chrome network data

![image](https://us1.discourse-cdn.com/elastic/original/3X/e/3/e31621caef650deb068ebb44018ed54cbbf4f359.png)

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/9/4/941be075650075708b5923b8d1097a1ba63f1d14.png)

THANK YOU for any advice.

---

<div class="post-metadata">

**Author:** ![Carlos\_D](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/carlos_d/32/126245_2.png) [@Carlos\_D](https://discuss.elastic.co/u/Carlos_D)\
**Post date:** [June 4, 2024, 3:41pm UTC](https://discuss.elastic.co/t/elastic-api-returns-401-from-browser-client-cors/360686/2 "2024-06-04T15:41:16Z")

</div>

Hey @qd-danh :

If you want to use regular expressions (other than `*`} in CORS settings, I believe you need to use forward slashes at the beginning and end of the regex - something similar to:

`/https?:\/\/.*\.static\.observableusercontent\.com/`

Please check the [documentation](https://www.elastic.co/guide/en/elasticsearch/reference/current/modules-network.html#http-settings) for the `http.cors.allow-origin` setting.
