#this work for cors only one is allowed location / { add_header 'Access-Control-Allow-Origin' '*' always; }
add_header Access-Control-Allow-Origin *;
location /api { add_header Access-Control-Allow-Origin *; }