CORS

Why curl works but browser JavaScript may fail.

A curl request can reach a webhook directly because it is not running inside a visitor's browser. Browser JavaScript has extra cross-site safety checks.

The common fix

Direct browser requests to PINGSLAP can fail due to CORS and expose your secret webhook URL to website visitors. Instead, send the browser submission to your own website first (such as /api/contact or a serverless endpoint). Your server reads the webhook URL from server-side environment configuration and forwards the alert server-to-server to PINGSLAP.

Browser form ↓ Your server or serverless function ↓ PINGSLAP webhook

See the Website Forms guide for a practical server-side implementation example.

Why curl worked

curl sends the request from your machine or server. It is not a web page loaded from another domain, so browser CORS rules are not involved.

Why browser JavaScript failed

A page at https://www.example.com calling https://api.example-service.test is cross-origin. The browser checks whether that receiving server allows the page to call it.

Why /api/contact helped

The browser posts to the same website it is already visiting. That is same-origin (avoiding browser CORS issues) and keeps your secret webhook URL protected on your server instead of exposed in frontend JavaScript.

What CORS does not control

Browser CORS rules do not govern the server-to-server forwarding request from your website server or reverse proxy to PINGSLAP.