Could you add an `Access-Control-Allow-Origin` header in the responses from https://twelve.cash/api/ to allow browser requests?