Skip to main content
Question

CORS issue while calling API through Figma Plugin


Rajath Kumar M

Team is facing this CORS issue while calling ChatID API through Figma Plugin in the Frontend.

Below is the error facing:
Access to fetch at 'https://******ChatId' from origin 'null' has been blocked by CORS policy: Request header field x-security-key is not allowed by Access-Control-Allow-Headers in preflight response.
VM374:6

2 replies

ksn
Figmate
  • Community Support
  • 1688 replies
  • July 1, 2025

Hey ​@Rajath Kumar M - I checked in with our team that works on extensibility on this. Do you own the API that you’re using?

Figma plugins use null origin iframes, which is blocked by the ChatID API. In the case you don’t own the API, try hosting your own site and navigating the plugin to it to make the requests: https://www.figma.com/plugin-docs/creating-ui/#non-null-origin-iframes.

 

Let me know if that doesn’t align with your issue ( ex: you do own the API in question). I can check again to see what other guidance may be helpful.


Rajath Kumar M

Thank you ​@ksn for your response.
We do not own API, and it’s a known thing that no server/api should support incoming request with Origin ‘null’. So we urgently need your support to close the issue, currently it is impacting our client delivery.

Appreciate your quick response to resolve this issue.


Reply


Cookie policy

We use cookies to enhance and personalize your experience. If you accept you agree to our full cookie policy. Learn more about our cookies.

 
Cookie settings