CORS Error While communicating within 2 application under Zero Trust Access

I had 2 applications of my website , which was working fine. and they were communicating smoothly with one another. One is front end and another is backend of the same website. Ever since I added my application to access tab in zero trust. I’m getting CORS error while sending request from one application to another

How are you handling auth with access? Is your application supplying credentials on the request?

I have added a rule in my api application to only serve requests from the main application URL.