I've found a fairly workable solution is to have an origin for the API in CloudFront and a behaviour to route /api/* to that origin. Saves any CORS headaches. Obviously this won't work in all cases.
(Of course, you can rewrite the URL on the fly via Lambda@Edge but that's a PITA to maintain)