Docs / Platform
CORS & browser security
Image embedding, canvas access, and server-side JSON requests.
Image and monogram responses from the beta endpoint include Access-Control-Allow-Origin: *. Image routes also handle OPTIONS for GET/HEAD with an Authorization header. Successful responses expose ETag and X-Brandmarks-* metadata to browser JavaScript, and image errors include the same CORS policy so clients can read the JSON error envelope.
For canvas use, set crossOrigin="anonymous" before setting the image source, and use a publishable-token URL. A plain image embed does not require a custom fetch call.
JSON endpoints intentionally do not enable browser CORS. Fetch search and company data from your server, and expose only the data your UI needs through your own endpoint.
Content Security Policy
Add the hostname you actually use to your existing img-src policy: the current API host is https://brandmarks-api.brandmarks-web.workers.dev; static links use the public R2 host shown in their URLs. Add connect-src only if your frontend fetches that resource directly. Preserve the rest of your application’s policy.
Static host CORS configuration is separate from API code; verify it before relying on canvas export from static URLs.
Need a hand? Get help · Technical content reviewed October 2, 2026