Access to XMLHttpRequest been blocked by CORS policy

I encounter this error when embedding a Threekit player:

Access to XMLHttpRequest at '{TOKEN}' from origin 'http://localhost:3000' has been blocked by CORS policy: No 'Access-Control-Allow-Origin' header is present on the requested resource.

There are two things this may be, check the docs for Embedding the Threekit Player for reference.

  1. Check that the script tag for the Threekit player matches your org environment. If you log in to Threekit at make sure your script tag is <script src=""></script>

  2. Make sure that your auth token is correct and authenticates the URL you are embedding on. For example, this token will load a player on localhost:3000 but not

