Allowed origins(cors)

In Auth0’s Allowed Origins (CORS), do we need to specify the origin even when accessing the token endpoint (/oauth/token) from a browser, for example?