<script> tags to the document.
Note that any JSONP requests will be processed as if logged out, even if the browser session is authenticated against the remote wiki.
For a CORS request to be allowed by the remote wiki,
$wgCrossSiteAJAXdomains must be set appropriately to allow the origin site. The MediaWiki API also requires that the origin be supplied as a request parameter, appropriately named "origin", which is matched against the Origin header required by the CORS protocol. Note that this header must be included in any pre-flight request, and so should be included in the query string portion of the request URI even for POST requests.
If the CORS origin check passes, MediaWiki will include the
Access-Control-Allow-Credentials: true header in the response, so authentication cookies may be sent.