Skip to content
FlexibleToolsAI
Security Toolkit · Free, Nothing Stored

CORS Checker

See how a URL responds to cross-origin requests. The checker sends a GET with the Origin you choose and a real OPTIONS preflight with Authorization, then explains the Access-Control headers — and flags dangerous setups like reflecting any origin with credentials.

Enter the endpoint URL and the Origin to test (an unrelated origin by default, to catch servers that trust everyone). Our server sends a simple GET with that Origin and a preflight request, and shows the Access-Control-Allow-Origin, -Credentials, -Methods and -Headers responses with a plain-English verdict for each.

the site that would make the request

Instant Results

Live checks in seconds

Nothing Stored

No logs of what you check

No Sign-Up

Free, no credits or email

Suggest a Feature or Improvement for CORS Checker

Need custom options, higher limits, or extra format support? Let our engineering team know!

How to use CORS Checker

  1. 1Enter the API or page URL.
  2. 2Set the Origin you want to test (e.g. your frontend).
  3. 3Choose the method for the preflight.
  4. 4Read the findings for both requests.

What CORS controls

CORS decides whether JavaScript running on one origin can read responses from another. Without Access-Control-Allow-Origin, browsers block the read — the safe default. Allow-Origin: * lets any site read public data but never with cookies.

The dangerous misconfiguration is reflecting whatever Origin the request sends and also returning Allow-Credentials: true. Then any website a logged-in user visits can read their private data from your API.

Fixing CORS errors

Allow specific origins from an allowlist, add Vary: Origin when the header depends on the request, answer OPTIONS preflights with the methods and headers you use, and only enable credentials when needed. CORS doesn't stop requests from being sent — protect state-changing endpoints with CSRF defences too.

Frequently Asked Questions

Why test with evil.example?

An unrelated origin reveals whether the server trusts any origin. Test your real frontend origin too, to confirm legitimate requests work.

Why does my browser still show a CORS error?

Check the preflight: if OPTIONS returns an error or lacks Allow-Methods/Allow-Headers for your request, the browser stops before sending it.

What do you do with the domains and URLs I check?

Our server performs the lookup once and returns the result to your browser. We don't store the addresses you check or build a history. Private and internal addresses are blocked.

Related Tools