← Back to all tools

CORS Checker

Check whether an origin can read a response for a specific request scenario.

Configure your request

Origin includes scheme, hostname and port — no path.

Credentials mode models browser rules. This checker does not send cookies, HTTP credentials, or your data to the target.

Checks permission for the selected method and requested header names.

Requested header names (optional)

Names only. Values for Authorization, Cookie, and other headers are not sent.

Two checks, one request scenario

Response access

Compare the returned origin and credentials headers with your request scenario.

Preflight permission

When enabled, check whether OPTIONS permits your method and header names.

Cross-origin access can be denied intentionally. Missing CORS headers do not automatically mean a misconfiguration.

How it works

  1. Enter the endpoint and frontend originProvide the target URL and the origin of your web application.
  2. Choose method and credentials modeSelect the request method and how credentials should be evaluated. Cookies are not sent.
  3. Review response and preflight separatelyThe response headers and, when requested, the OPTIONS result are reported on their own.

Frequently asked questions

What is an origin?

An origin is a scheme, hostname, and port. It does not include a path, query, or fragment. Default ports 80 and 443 are omitted.

When is preflight required?

A browser sends OPTIONS before some cross-origin requests, including methods other than GET, HEAD, and POST, and before non-safelisted header names. This checker sends OPTIONS when you enable the option, when the method is not GET or HEAD, or when you name a non-safelisted header.

Does a denied result mean the site is broken?

No. A server can refuse cross-origin reads on purpose. A missing Access-Control-Allow-Origin is a denial for this scenario, not automatically a misconfiguration.

Does this checker reproduce a browser exactly?

No. It runs on the server. It does not execute a browser, and it does not confirm CSP connect-src, mixed content, or cookie policies. Redirects are recorded and left indeterminate when they are not evaluated as a browser CORS redirect.