Skip to main content
The Cognite Data Fusion (CDF) API uses registered applications to enforce cross-origin resource sharing (CORS). An application contains a list of allowed Origin values. CDF checks the Origin header on a request against those values. The origin must match a pattern in at least one application registered to the project that the request targets.

Access control

To list or retrieve applications, the caller must be signed in to the target organization or be an admin in any of its ancestor organizations. To create, update, or delete applications, the caller must be an admin of the target organization or an admin in any of its ancestor organizations.
Last modified on October 7, 2026