aiohttp-cors
CORS support for aiohttp
Decision gist · record as of 2026-08-14
Yes, if you are building an aiohttp application that needs to serve cross-origin requests from browsers. The package has low install friction, active maintenance, permissive licensing, and no known vulnerabilities. The Alpha status reflects the library's maturity rather than instability—it has been in use since 2015. Install it when you need CORS support; skip it if your API is same-origin only or uses alternative cross-origin strategies.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Requires Python 3.9 or later and an existing aiohttp application to configure.
- Low install friction with a single runtime dependency on aiohttp.
- The package is actively maintained with a recent release in March 2025 and ongoing repository activity, though classified as Alpha development status.
License · maintenance · safety
Apache License, Version 2.0 (permissive) — Licensed under Apache License 2.0 (permissive), allowing commercial and private use with minimal restrictions—suitable for most projects that can accommodate attribution.
last release 2025-03-31 (501 days) · last repo commit 2026-08-14 · 220 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 19,173,377 downloads/mo, #1,072 on PyPI
Alternatives
Verify before relying
pip install aiohttp-cors
import aiohttp_cors
from aiohttp import web
app = web.Application()
cors = aiohttp_cors.setup(app)
resource = cors.add(app.router.add_resource("/hello"))
cors.add(resource.add_route("GET", handler), {
"http://client.example.org": aiohttp_cors.ResourceOptions(
allow_credentials=True,
expose_headers=("X-Custom-Server-Header",),
)
})- Whether the Alpha development status reflects active feature development or stable maintenance with conservative versioning.
- Performance characteristics when handling high volumes of preflight requests or complex CORS configurations.
What it is and what it does
aiohttp_cors is a middleware library that implements the CORS standard for aiohttp, an async HTTP server framework. It solves the problem of allowing web browsers to make cross-origin requests to your server by handling the browser's same-origin policy restrictions through proper HTTP headers and preflight request handling. The library lets you configure which origins can access specific routes, whether credentials are allowed, which headers clients can send, and which headers the server exposes back to clients.
You configure CORS per route by wrapping resources and routes through the library's API, specifying allowed origins and their associated options. The package handles both simple requests (which include the Origin header) and preflight requests (OPTIONS method queries that browsers send before complex requests). It supports wildcard origins for permissive configurations and per-origin customization for fine-grained control.
Use it for
- Enable a single-page application served from a different domain to make API calls to your aiohttp server.
- Allow mobile apps or desktop clients to access your async HTTP API without browser same-origin restrictions.
- Configure different CORS policies for different routes—strict for sensitive endpoints, permissive for public APIs.
- Handle preflight caching to reduce browser OPTIONS requests and improve client-side performance.
- Expose custom response headers to browser clients while controlling which request headers are accepted.
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes, if you are building an aiohttp application that needs to serve cross-origin requests from browsers.
The package has low install friction, active maintenance, permissive licensing, and no known vulnerabilities. The Alpha status reflects the library's maturity rather than instability—it has been in use since 2015. Install it when you need CORS support; skip it if your API is same-origin only or uses alternative cross-origin strategies.
Install
aiohttp-cors on PyPI
Before you install
Low install friction with a single runtime dependency on aiohttp. The package is actively maintained with a recent release in March 2025 and ongoing repository activity, though classified as Alpha development status.
Requires Python 3.9 or later and an existing aiohttp application to configure.
License in practice
Licensed under Apache License 2.0 (permissive), allowing commercial and private use with minimal restrictions—suitable for most projects that can accommodate attribution.
Quickstart
pip install aiohttp-cors
import aiohttp_cors
from aiohttp import web
app = web.Application()
cors = aiohttp_cors.setup(app)
resource = cors.add(app.router.add_resource("/hello"))
cors.add(resource.add_route("GET", handler), {
"http://client.example.org": aiohttp_cors.ResourceOptions(
allow_credentials=True,
expose_headers=("X-Custom-Server-Header",),
)
})
Verify before relying
- Whether the Alpha development status reflects active feature development or stable maintenance with conservative versioning.
- Performance characteristics when handling high volumes of preflight requests or complex CORS configurations.
Package facts
| License | Apache License, Version 2.0 permissive |
| Python support | Supports the current Python release >=3.9 |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | 1 packageaiohttp |
| Maintenance | Actively maintained 501 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 19,173,377 / month, #1,072 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Development Status :: 3 - AlphaFramework :: AsyncIOFramework :: aiohttpIntended Audience :: DevelopersLicense :: OSI Approved :: Apache Software LicenseOperating System :: MacOS :: MacOS XOperating System :: Microsoft :: WindowsOperating System :: POSIXProgramming Language :: PythonProgramming Language :: Python :: 3Topic :: Internet :: WWW/HTTPTopic :: Software Development :: Libraries |
Evidence: aiohttp_cors-0.8.1-py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “browser cors headers aiohttp”
- aiohttp-corsAdds Cross-Origin Resource Sharing (CORS) support to aiohttp…
- quart-corsQuart-CORS adds Cross-Origin Resource Sharing (CORS) support to Quart…
- django-cors-headersAdds Cross-Origin Resource Sharing (CORS) headers to Django…
Give your agent the search over MCP, or paste the wish link into any chat.
More Libraries packages
urllib3 is an HTTP client library that provides thread-safe connection pooling, SSL/TLS verification, multipart file uploads, request retries, compression support, and proxy handling for Python applications.
Requests is a Python HTTP library that simplifies sending HTTP/1.1 requests with automatic handling of headers, authentication, cookies, and response parsing.
Pluggy provides a plugin system that lets you define hook specifications and register implementations to be called in sequence, enabling extensible Python applications without tight coupling.
Install it if you're building an extensible application or framework.
Provides parsing, arithmetic, and recurrence rule computation for dates and times, with timezone support and iCalendar RFC compliance.
Install it if you need to parse flexible date strings, compute relative dates, handle timezones, or work with recurrence rules—it's the de facto choice for these tasks.
Six provides utility functions to write Python code that runs on both Python 2.7 and Python 3.3+, smoothing over language differences between the two versions.
pytest is a testing framework that lets you write test functions using plain assert statements and automatically discovers and runs them, with detailed failure reporting.
See also aiohttp-middlewares · django-cors-headers · fastapi-cors · quart-cors · cherrypy-cors · flask-cors · Sanic-Cors · invenio-rest · aiohttp-basicauth · aiohttp-swagger3