# Simulator OK, but Published build fails with CORS (OpenAI + Flask via ngrok)

**URL:** <https://forum.8thwall.com/t/simulator-ok-but-published-build-fails-with-cors-openai-flask-via-ngrok/6655>\
**Category:** Technical Support\
**Tags:** FAQ, general\
**Created:** [May 27, 2025, 6:17am UTC](https://forum.8thwall.com/t/simulator-ok-but-published-build-fails-with-cors-openai-flask-via-ngrok/6655 "2025-05-27T06:17:25Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![chow\_kenny](https://avatars.discourse-cdn.com/v4/letter/c/ed8c4c/32.png) [@chow\_kenny](https://forum.8thwall.com/u/chow_kenny)\
**Post date:** [May 27, 2025, 6:17am UTC](https://forum.8thwall.com/t/simulator-ok-but-published-build-fails-with-cors-openai-flask-via-ngrok/6655/1 "2025-05-27T06:17:25Z")

</div>

Dear 8th Wall Staff,  
I’m building a small prototype that chains **8th Wall (front-end) → Flask (ngrok tunnel) → OpenAI** to generate story text from user-uploaded photos.

_ **1 · Setup in short** _  
**[8**th Wall Web] ---- fetch (multipart/form-data, POST /upload\_image) ----\> [ngrok [https://niko.ngrok.app](https://niko.ngrok.app)] ---- Flask (flask-cors) ----\> OpenAI API

- **Front-end** : simple A-Frame scene, user chooses an image → `fetch()` to `/upload_image`.
- **Back-end** : Flask server on localhost :5000, exposed through `ngrok http 5000 --domain niko.ngrok.app`.
- **CORS** : `flask_cors.CORS(app, resources={r"/*": {"origins": "*"}})` for now, just to debug.

_ **2 · What works** _

- **8th Wall Cloud Editor → Simulator** (dev URL `*.dev.8thwall.app`):  
the request reaches Flask, OpenAI replies, story shows up.

 ![2](https://us1.discourse-cdn.com/flex019/uploads/x8thwall/original/2X/f/fea1f3821f76530212b8828c5dbeb3bab8cab243.jpeg)

##### 3 _· What fails after “Publish”_

- **Staging / Public URL** (`https://kennychow.8thwall.app/...`) shows the UI, but when I press **Generate Next Chapter** the request is blocked:

Access to fetch at ‘[https://niko.ngrok.app/upload\_image](https://niko.ngrok.app/upload_image)’  
from origin ‘[https://kennychow.8thwall.app](https://kennychow.8thwall.app)’  
has been blocked by CORS policy:  
Response to preflight request doesn’t pass access control check:  
No ‘Access-Control-Allow-Origin’ header is present on the requested resource.

DevTools console also reports `net::ERR_FAILED` on the OPTIONS preflight.

Simulator uses the exact same ngrok endpoint and works, so I’m guessing this is either:

1. **CSP / External Domains whitelist** for published builds
2. Some extra CORS header 8th Wall adds in production

 ![Fail1](https://us1.discourse-cdn.com/flex019/uploads/x8thwall/original/2X/4/4c9464aea0482084fc893a5960b993b92eed7a2d.png)  
 ![Screenshot 2025-05-27 104020](https://us1.discourse-cdn.com/flex019/uploads/x8thwall/original/2X/e/e926fdf7843a7e863120376d7bb45f482509e033.png)

##### _4 · Things I’ve tried_

- Added `https://*.8thwall.app` and `https://niko.ngrok.app` to `origins="*"` (just for debug).
- Couldn’t find **Hosting & Domains → External Domains / CSP** section in Project Settings (I’m on the free “Basic” workspace).

##### _5 · Questions_

1. For Basic workspaces, is there still a way to whitelist `niko.ngrok.app` so the published domain can fetch it?
2. If not, what’s the recommended pattern for calling an external Flask/OpenAI endpoint from a published 8th Wall project?
3. Any other headers I should add on the Flask side to satisfy the OPTIONS preflight?  
My Project Link:8th.io/vgx3p

Thanks in advance!

---

<div class="post-metadata">

**Author:** ![GeorgeButler](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.8thwall.com/georgebutler/32/1903_2.png) [@GeorgeButler](https://forum.8thwall.com/u/GeorgeButler)\
**Post date:** [May 27, 2025, 10:05pm UTC](https://forum.8thwall.com/t/simulator-ok-but-published-build-fails-with-cors-openai-flask-via-ngrok/6655/2 "2025-05-27T22:05:48Z")

</div>

Can you confirm that you’re seeing the `allow all *` wildcard in the response headers from your server? It could be that the ngrok tunnel is preventing this configuration and instead you need to use a cloud hosting provider for your server.

---

<div class="post-metadata">

**Author:** ![chow\_kenny](https://avatars.discourse-cdn.com/v4/letter/c/ed8c4c/32.png) [@chow\_kenny](https://forum.8thwall.com/u/chow_kenny)\
**Post date:** [May 28, 2025, 3:42am UTC](https://forum.8thwall.com/t/simulator-ok-but-published-build-fails-with-cors-openai-flask-via-ngrok/6655/3 "2025-05-28T03:42:22Z")

</div>

Thanks for your reply, I will check my ngrok tunnel setting.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex019/uploads/x8thwall/original/2X/9/9212a857458f1b03a6accb129e0f8cbea408e3e5.png) [@system](https://forum.8thwall.com/u/system)\
**Post date:** [June 1, 2025, 3:42am UTC](https://forum.8thwall.com/t/simulator-ok-but-published-build-fails-with-cors-openai-flask-via-ngrok/6655/4 "2025-06-01T03:42:24Z")

</div>

This topic was automatically closed 4 days after the last reply. New replies are no longer allowed.
