diff --git a/config/initializers/cors.rb b/config/initializers/cors.rb
index 681a7498f969b702f4a888c434d0fdc5bce7ac0b..36d3663cb493e9303dea109dd4a2a15327419b6b 100644
--- a/config/initializers/cors.rb
+++ b/config/initializers/cors.rb
@@ -9,6 +9,10 @@ Rails.application.config.middleware.insert_before 0, Rack::Cors do
   allow do
     origins '*'
 
+    resource '/.well-known/*',
+      headers: :any,
+      methods: [:get],
+      credentials: false
     resource '/@:username',
       headers: :any,
       methods: [:get],