$allowedOrigins = [ "http://www.websiteA.com", "https://www.websiteB.com" // ... etc ]; if (in_array($_SERVER["HTTP_ORIGIN"], $allowedOrigins)) { header("Access-Control-Allow-Origin: " . $_SERVER["HTTP_ORIGIN"]); }