В общем решил так
1) Убрал в Lumen в /bootstrap/app.php middleware Cors,
2) в nginx в site.conf добавил
add_header 'Access-Control-Max-Age' 86400;
add_header 'Access-Control-Allow-Origin' "
new.site.kz" always;
add_header 'Access-Control-Allow-Credentials' 'true' always;
add_header 'Access-Control-Allow-Methods' 'GET, POST, PUT, DELETE, OPTIONS' always;
add_header 'Access-Control-Allow-Headers' 'Accept, Authorization, Cache-Control, Content-Type, Keep-Alive, Origin, User-Agent, X-Requested-With' always;
add_header 'Access-Control-Expose-Headers' 'Authorization, X-RateLimit-Limit, X-RateLimit-Remaining, X-RateLimit-Reset' always;