Middleware & Error Handling
Add CORS, request IDs, and consistent exception handlers.
Search across all documentation pages
Add CORS, request IDs, and consistent exception handlers.
Quick-reference recipe card - copy-paste ready.
from fastapi import FastAPI, Request
from fastapi.middleware.cors import CORSMiddleware
app = FastAPI()
app.add_middleware(CORSMiddleware, allow_origins=["https://app.example"], allow_methods=["*"], allow_headers=["*"])
@app.middleware("http")
async def add_request_id(request: Request, call_next):
response = await call_next(request)
response.headers["X-Request-Id"] = request.headers.get("X-Request-Id", "generated")
return responseWhen to reach for this:
from fastapi import FastAPI, HTTPException, Request
from fastapi.responses import JSONResponse
app = FastAPI()
class AppError(Exception):
def __init__(self, code: str, status: int = 400):
self.code = code
self.status = status
@app.exception_handler(AppError)
async def app_error_handler(_: Request, exc: AppError):
return JSONResponse(status_code=exc.status, content={"error": exc.code})
@app.get("/boom")
def boom():
raise AppError("invalid_state", 422)What this demonstrates:
add_middleware order.| Alternative | Use When | Don't Use When |
|---|---|---|
| Alternate framework in this cookbook | Team standard or existing monolith | Greenfield API with different constraints |
| Managed BaaS | CRUD-only MVP | Custom auth, workflows, or compliance needs |
| gRPC | Internal high-performance RPC | Public HTTP clients and browser access |
Use it when the patterns and trade-offs on this page match your API or data boundary.
Skipping validation, timeouts, or explicit error contracts at the HTTP edge.
Use the framework test client, override dependencies, and assert status plus JSON shape.
Yes - examples target Python 3.14 with pinned framework versions from the stack footer.
Validate and serialize at boundaries; keep services working with typed domain objects.
Prefer async routes when I/O dominates; keep CPU work small or offload to workers.
Thin handlers; services own rules; repositories own queries.
Publish OpenAPI or schema docs that match response models in code.
Explicit URL or header versioning with deprecation windows - avoid silent breaks.
Follow the Related links for the next layer of depth in this section.
Authenticate callers, authorize per resource, rate-limit, and never log secrets.
Measure DB and upstream latency before swapping frameworks.
Stack versions: This page was written for Python 3.14.0 (stable 3.14, maintenance 3.13), FastAPI 0.115+, Django 5.2, Flask 3.1, Pydantic 2, PyTorch 2.6+, pandas 2.2+, Polars 1.x, ruff 0.9+, and uv 0.6+.
Reviewed by Chris St. John·Last updated Jul 19, 2026