# Allowed origins

> Restrict which websites can submit to a form. Allowed origins stop other sites from using your endpoint and set CORS headers.

Source: https://sitebackend.com/docs/forms/allowed-origins · Updated: 2026-10-09

By default, any website can submit to a form's endpoint. Allowed origins restrict each form to your own domains.

## How do I set allowed origins?

Open **Form → Settings → Allowed origins** and add one origin per line:

```txt
https://example.com
https://www.example.com
```

An origin is the scheme and host, plus the port if it isn't the default: `https://example.com`, `http://localhost:4321`. Paths are ignored, so `https://example.com/contact` is saved as `https://example.com`. Each form has its own list, so a form embedded on two sites can allow both.

## What happens to other origins?

Submissions from any other origin are rejected with `403 This site is not allowed to submit to this form`. SiteBackend reads the browser's `Origin` header, or the `Referer` when there's no `Origin`.

> **Warning:** Add your local development address too, for example `http://localhost:4321`, or your form will stop working while you develop.

## Does this affect CORS?

Yes. For `fetch` requests, SiteBackend returns your origin in `Access-Control-Allow-Origin` when it's allowed. With no allowed origins set on the form, it returns `*`.

## Do allowed origins apply to testimonials?

No. Allowed origins are set per form. Testimonial collect forms and widgets use the site's **domain** instead: set it in **Site → Settings** and they only load on that domain, its subdomains and `localhost`. See [sites](https://sitebackend.com/docs/getting-started/sites).
