Recommended Free Tools
iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
Angular error NG02800 means an app made a JSONP request without enabling JSONP in its HttpClient configuration. For a legacy app that must keep JSONP, enable it using the setup that matches the app’s bootstrap style. Angular’s current documentation deprecates its JSONP APIs because they can cause XSS vulnerabilities and recommends standard HTTP requests with CORS instead.
Angular’s NG02800 reference documents both configuration fixes.
Choose the fix that matches your Angular bootstrap setup
The two remedies are alternatives: use the provider-based option for apps configured with provideHttpClient(), or the module option for an NgModule-based app. These enable the legacy JSONP feature; they do not change the endpoint or migrate it to CORS.
Free tools Windows power users keep installed
One-click scans. No signup required.
Provider-based configuration
Add withJsonpSupport() to the existing provideHttpClient() call. For example:
#1 Best Overall
import { provideHttpClient, withJsonpSupport } from '@angular/common/http';
export const appConfig = {
providers: [provideHttpClient(withJsonpSupport())],
};
Adapt this to the app’s existing configuration rather than replacing unrelated providers. Angular documents this remedy in its NG02800 reference.
NgModule-based bootstrap
For an NgModule-based app, import HttpClientJsonpModule in the root AppModule, as described in the error reference. Angular’s module API documentation explains that without this module, JSONP requests reach the backend with the JSONP method and are rejected.
Rank #2
What NG02800 does—and does not—mean
The error identifies missing JSONP support in the client configuration. It does not, by itself, mean that the endpoint returned malformed JSON. If the app still fails after enabling the feature, investigate the endpoint and request separately; NG02800 alone does not establish their cause.
Should you keep JSONP or move to CORS?
For current Angular development, prefer a standard HTTP request with CORS when the endpoint and deployment can support it. Angular’s HTTP guide describes withJsonpSupport() as enabling .jsonp() for a GET request using the JSONP convention, then advises preferring CORS. Angular’s current API documentation states: “JSONP is deprecated as it can cause XSS vulnerabilities. Use standard HTTP requests instead.” See the withJsonpSupport API and HttpClient API.
Rank #3
The JSONP APIs—withJsonpSupport(), HttpClientJsonpModule, and HttpClient.jsonp()—are marked deprecated since Angular v22.1 in the current API documentation. Enabling JSONP may be a practical compatibility fix for a legacy integration, but it retains a deprecated feature and its stated security concern.
CORS is not enabled merely by changing Angular’s client. The server and browser request must also be compatible with the application’s endpoint and deployment. Angular’s guidance recommends the direction of migration, but does not provide a complete endpoint migration checklist.
Quick Recap
Rank #4
Use the right fix for the problem
- Need to keep an existing JSONP integration: enable support using the configuration route for the app’s bootstrap style.
- Can change the integration: move to a standard HTTP request and arrange for the endpoint and deployment to support CORS, following Angular’s current recommendation.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

