How to Configure Joomla Web Services Settings

Joomla's Global Configuration includes Web Services settings for Cross-Origin Resource Sharing (CORS). These controls determine whether browser-based code from another origin may make cross-origin requests to Joomla web-service routes and what CORS response information Joomla supplies.

Open the Web Services settings

  1. Sign in to Joomla Administrator.
  2. Open System → Setup Panel → Global Configuration.
  3. Open the Server tab.
  4. Locate the Web Services section.

Decide whether CORS is actually required

Enable Enable CORS only when browser code hosted on a different origin must call your Joomla web services. A server-to-server integration is not governed by browser CORS enforcement in the same way, so enabling CORS is not a general fix for API connectivity.

Configure the allowed CORS response values

  • Access-Control-Allow-Origin specifies the origin Joomla allows in the CORS response. Joomla's help documents * as the default, meaning all origins. For a controlled integration, use the narrow origin required by the application when its design permits that.
  • Access-Control-Allow-Headers specifies headers returned for a preflight request. Joomla documents the default as Content-Type,X-Joomla-Token.
  • Access-Control-Allow-Methods specifies methods allowed for the requested web-service route; Joomla documents the default as all methods available for that route.

Select Save after making the required changes.

CORS does not grant Joomla permissions

CORS controls browser cross-origin access; it does not authenticate a caller or grant Joomla authorization. Joomla separately provides a Web Services Login permission in Global Configuration. API authentication, enabled web-service plugins/routes, and the permissions required by the requested resource must also be correct.

Verify with the real client

Test from the exact browser origin and request method used by the integration. If the browser sends a preflight request, inspect its response headers and status. A CORS error can be caused by an origin/header/method mismatch, while a 401 or 403 response can instead indicate authentication or authorization. Do not broaden allowed origins merely to hide an unrelated API error.

Security check

Treat cross-origin access as part of the integration's security design. Allow only what the client requires, keep authentication tokens protected, and retest after changing domains, reverse proxies, or API clients.


Need More Help with Joomla?

Still having trouble? Open a support ticket with QuantaCade Support and we'll be happy to help where we can.

Support priority is given to QuantaCade products, services, and customers. However, we're also happy to assist fellow Joomla users with general Joomla questions and troubleshooting when possible.

QuantaCade is an independent Joomla extension developer and is not official Joomla support. Some issues involving third-party extensions, hosting environments, server configurations, or other systems outside our development control may be beyond what we're able to resolve.

Open a Support Ticket