CORS CHECKER

Check CORS configuration for any URL. Test preflight requests and inspect Access-Control headers to debug cross-origin issues.

TARGET URL
QUICK EXAMPLES
ABOUT CORS

What is CORS?

Cross-Origin Resource Sharing (CORS) is a browser security mechanism that controls how web pages can request resources from different domains. When your frontend on one domain calls an API on another domain, the browser enforces CORS.

How This Tool Works

This tool sends both a preflight OPTIONS request and an actual GET request to your target URL with the specified origin header. It then reports which CORS headers were present in each response, whether the origin was allowed, and whether wildcard access was granted.

Common CORS Headers

  • Access-Control-Allow-Origin — which origins are permitted
  • Access-Control-Allow-Methods — which HTTP methods are allowed
  • Access-Control-Allow-Headers — which request headers are permitted
  • Access-Control-Allow-Credentials — whether cookies/auth are sent
  • Access-Control-Max-Age — how long preflight results are cached