["follow", "write_message", "read_messages", "edit_account", "delete_account"]

["default", "basic", "edit", "show_secret"]

Problems

Access-Control-Allow-Origin: *

when responding to a credentialed request, server must specify a domain, and cannot use wild carding.

*

null

Access-Control-Allow-Origin