Permit Javascript-based web applications hosted on other servers than the API server to send requests to the API. Use https://github.com/cyu/rack-cors. See also: - http://dev.housetrip.com/2014/04/17/unleash-your-ajax-requests-with-cors/ - http://blog.rudylee.com/2013/10/29/rails-4-cors/ - http://stackoverflow.com/questions/29751115/how-to-enable-cors-in-rails-4-app