Allow-Origin
Access-Control-Allow-Origin must match the requesting Origin, or use * for eligible non-credentialed requests.
Will this API allow a browser request from your Origin? Inspect the preflight and actual response separately, then see exactly which origin, method, header or credential rule affects browser access.
Enter the public endpoint and the exact Origin that browser JavaScript would send.
Run a test to compare preflight and actual response headers with the requested browser operation.
The browser asks permission before the actual operation.
The endpoint can respond successfully while the browser still blocks JavaScript from reading it.
Each result is evaluated against the Origin, method, headers and credential mode entered above.
CORS is a browser access policy, not a general security score.
https://app.example.com or http://localhost:3000, without a path.Access-Control-Allow-Origin must match the requesting Origin, or use * for eligible non-credentialed requests.
Access-Control-Allow-Methods lists methods accepted by the preflight policy. It matters when a preflight is required.
Access-Control-Allow-Headers must permit each non-simple request header. Header values and secrets are never needed for this test.
Access-Control-Allow-Credentials: true is required when JavaScript uses credential mode. A wildcard origin is incompatible with that mode.
Access-Control-Expose-Headers identifies additional response headers browser JavaScript may read.
Access-Control-Max-Age controls preflight caching. Vary: Origin helps shared caches separate origin-specific responses.
* for a non-credentialed GET.https://app.example.com and permit Authorization after validating that Origin.The tester evaluates response headers from the Netest server. Browser behavior can also depend on request mode, credentials, redirects, service workers and browser implementation. Authenticated endpoints may return different CORS policies after login.
No cookies, Authorization values, API keys or request bodies are accepted or sent. POST, PUT, PATCH and DELETE are represented only in OPTIONS preflight headers; the tool never executes those state-changing methods.
Targets must be public HTTP or HTTPS endpoints on standard web ports. Every redirect is resolved and validated again, at most five redirects are followed, requests stop after 10 seconds, response bodies are capped, and repeated use is rate-limited.
This tool does not prove that an API is secure or insecure. Use it only with public endpoints you are authorized to test.
The Origin is only placed into an HTTP header. The tester does not connect to that Origin. The target URL itself still cannot use localhost or private addressing.
Non-simple methods and headers normally trigger OPTIONS before the actual request. This tool conservatively preflights any listed requested header.
Credentialed browser requests require a specific matching Allow-Origin value; * cannot authorize credentialed response sharing.
No. The preflight response must also permit the Origin, requested method and requested headers, and credential rules must be compatible.
Servers can apply different middleware or routing to OPTIONS and GET. Both responses need compatible CORS headers for a preflighted GET.
No. Enter the header name Authorization only. Never paste a token, cookie, password or API key into this tool.