For certain cross-origin requests, the browser first sends OPTIONS. It checks the server response for allowed origin, method, and headers before sending the actual request.
In the demo, an allowed preflight leads to POST; a denied one stops at the browser. CORS controls browser access to responses and does not replace server authentication.
When to use
Inspect preflight response headers when a browser blocks a cross-origin API call.