Response access
Compare the returned origin and credentials headers with your request scenario.
Check whether an origin can read a response for a specific request scenario.
Compare the returned origin and credentials headers with your request scenario.
When enabled, check whether OPTIONS permits your method and header names.
Cross-origin access can be denied intentionally. Missing CORS headers do not automatically mean a misconfiguration.
An origin is a scheme, hostname, and port. It does not include a path, query, or fragment. Default ports 80 and 443 are omitted.
A browser sends OPTIONS before some cross-origin requests, including methods other than GET, HEAD, and POST, and before non-safelisted header names. This checker sends OPTIONS when you enable the option, when the method is not GET or HEAD, or when you name a non-safelisted header.
No. A server can refuse cross-origin reads on purpose. A missing Access-Control-Allow-Origin is a denial for this scenario, not automatically a misconfiguration.
No. It runs on the server. It does not execute a browser, and it does not confirm CSP connect-src, mixed content, or cookie policies. Redirects are recorded and left indeterminate when they are not evaluated as a browser CORS redirect.