CORS
Why curl works but browser JavaScript may fail.
A curl request can reach a webhook directly because it is not running inside a visitor's browser. Browser JavaScript has extra cross-site safety checks.
The common fix
Direct browser requests to PINGSLAP can fail due to CORS and expose your secret webhook URL to website visitors. Instead, send the browser submission to your own website first (such as /api/contact or a serverless endpoint). Your server reads the webhook URL from server-side environment configuration and forwards the alert server-to-server to PINGSLAP.
Browser form
↓
Your server or serverless function
↓
PINGSLAP webhook
See the Website Forms guide for a practical server-side implementation example.
Why curl worked
curl sends the request from your machine or server. It is not a web page loaded from another domain, so browser CORS rules are not involved.
Why browser JavaScript failed
A page at https://www.example.com calling https://api.example-service.test is cross-origin. The browser checks whether that receiving server allows the page to call it.
Why /api/contact helped
The browser posts to the same website it is already visiting. That is same-origin (avoiding browser CORS issues) and keeps your secret webhook URL protected on your server instead of exposed in frontend JavaScript.
What CORS does not control
Browser CORS rules do not govern the server-to-server forwarding request from your website server or reverse proxy to PINGSLAP.
Recommended path
- Do not put webhook URLs in frontend JavaScript: Direct browser requests expose your webhook URL in page source and network inspection, and frequently run into cross-origin browser blocks.
- Use a server-side route: For browser forms, submit to a same-origin endpoint (such as
/api/contact) or serverless handler. See Website Forms for a practical server-side example.
- Direct server-to-server systems: Backend applications, automation platforms (n8n, Zapier, Make), and server-side WordPress plugins already execute on private servers. Because they do not ship the webhook URL to visitors' browsers, they do not need this proxy and can send directly to PINGSLAP.
- Keep secrets server-side: Store the webhook URL in server environment configuration and exclude it from public version control.
- After the route is connected, run Verify Integration.