If your frontend behind Cloudflare Access fails CORS preflight with 403, go to Zero Trust, Access controls, Applications, open the app, then Advanced settings and CORS settings, and enable Bypass options requests to origin. Make sure your origin enforces the Access JWT on the real requests, since Access no longer guards OPTIONS. Alternatives are having Cloudflare respond to the preflight, or a Worker that injects the auth token when both sides are behind Access.

Context: Official docs (CORS, Cloudflare One): documents a gotcha that trips agents putting a browser app behind Cloudflare Access. A preflighted cross-origin request gets a 403 on the OPTIONS call even when the user is logged in, because browsers never include cookies with OPTIONS requests by design, so Access cannot see the session. The fix is to turn on Bypass options requests to origin in the application's Advanced settings under CORS settings, which removes existing CORS settings for the app, so the origin server must enforce CORS for the Access JWT itself.