HTTP protocol tool

CORS Tester

Will this API allow a browser request from your Origin? Inspect the preflight and actual response separately, then see exactly which origin, method, header or credential rule affects browser access.

Browser-style preflightSends OPTIONS when the requested operation requires it.
Policy-by-policy checksExplains origin, method, headers, credentials and cache variation.
Safe public testingPrivate targets, secrets, bodies and state-changing requests are blocked.

Test a browser cross-origin request

Enter the public endpoint and the exact Origin that browser JavaScript would send.

A URL without a protocol is normalized to HTTPS. The target must resolve to a public address on port 80 or 443.
Use only scheme://host[:port]. Localhost is valid here because it is sent only as a header value.
Enter header names only. Do not enter API keys, tokens or credentials.
This changes interpretation only. No cookies or credentials are sent.

Run a test to compare preflight and actual response headers with the requested browser operation.

How to use the CORS tester

  1. Enter the public API or website URL, including the endpoint path you want a browser application to call.
  2. Enter the browser application's Origin, such as https://app.example.com or http://localhost:3000, without a path.
  3. Select the intended method and list only requested header names, separated by commas.
  4. Choose whether the browser request would use credentials, then compare the preflight and actual GET policies.

What each CORS response header means

Allow-Origin

Access-Control-Allow-Origin must match the requesting Origin, or use * for eligible non-credentialed requests.

Allow-Methods

Access-Control-Allow-Methods lists methods accepted by the preflight policy. It matters when a preflight is required.

Allow-Headers

Access-Control-Allow-Headers must permit each non-simple request header. Header values and secrets are never needed for this test.

Allow-Credentials

Access-Control-Allow-Credentials: true is required when JavaScript uses credential mode. A wildcard origin is incompatible with that mode.

Expose-Headers

Access-Control-Expose-Headers identifies additional response headers browser JavaScript may read.

Max-Age and Vary

Access-Control-Max-Age controls preflight caching. Vary: Origin helps shared caches separate origin-specific responses.

Practical examples and interpretation

Limitations, privacy and responsible use

The tester evaluates response headers from the Netest server. Browser behavior can also depend on request mode, credentials, redirects, service workers and browser implementation. Authenticated endpoints may return different CORS policies after login.

No cookies, Authorization values, API keys or request bodies are accepted or sent. POST, PUT, PATCH and DELETE are represented only in OPTIONS preflight headers; the tool never executes those state-changing methods.

Targets must be public HTTP or HTTPS endpoints on standard web ports. Every redirect is resolved and validated again, at most five redirects are followed, requests stop after 10 seconds, response bodies are capped, and repeated use is rate-limited.

This tool does not prove that an API is secure or insecure. Use it only with public endpoints you are authorized to test.

CORS tester FAQ

Why is localhost allowed as an Origin?

The Origin is only placed into an HTTP header. The tester does not connect to that Origin. The target URL itself still cannot use localhost or private addressing.

When is preflight required?

Non-simple methods and headers normally trigger OPTIONS before the actual request. This tool conservatively preflights any listed requested header.

Why is wildcard plus credentials rejected?

Credentialed browser requests require a specific matching Allow-Origin value; * cannot authorize credentialed response sharing.

Does OPTIONS 204 guarantee success?

No. The preflight response must also permit the Origin, requested method and requested headers, and credential rules must be compatible.

Why compare preflight and GET?

Servers can apply different middleware or routing to OPTIONS and GET. Both responses need compatible CORS headers for a preflighted GET.

Can I provide an API token?

No. Enter the header name Authorization only. Never paste a token, cookie, password or API key into this tool.

Related tools and guidance