Browsers attach an Origin header and may send a preflight request before methods or headers considered non-simple. The server returns permission headers that the browser enforces for script access. CORS is not authentication and does not prevent non-browser clients from sending requests.