CORS Checker
See how a URL responds to cross-origin requests. The checker sends a GET with the Origin you choose and a real OPTIONS preflight with Authorization, then explains the Access-Control headers — and flags dangerous setups like reflecting any origin with credentials.
Enter the endpoint URL and the Origin to test (an unrelated origin by default, to catch servers that trust everyone). Our server sends a simple GET with that Origin and a preflight request, and shows the Access-Control-Allow-Origin, -Credentials, -Methods and -Headers responses with a plain-English verdict for each.
Instant Results
Live checks in seconds
Nothing Stored
No logs of what you check
No Sign-Up
Free, no credits or email
Suggest a Feature or Improvement for CORS Checker
Need custom options, higher limits, or extra format support? Let our engineering team know!
How to use CORS Checker
- 1Enter the API or page URL.
- 2Set the Origin you want to test (e.g. your frontend).
- 3Choose the method for the preflight.
- 4Read the findings for both requests.
What CORS controls
CORS decides whether JavaScript running on one origin can read responses from another. Without Access-Control-Allow-Origin, browsers block the read — the safe default. Allow-Origin: * lets any site read public data but never with cookies.
The dangerous misconfiguration is reflecting whatever Origin the request sends and also returning Allow-Credentials: true. Then any website a logged-in user visits can read their private data from your API.
Fixing CORS errors
Allow specific origins from an allowlist, add Vary: Origin when the header depends on the request, answer OPTIONS preflights with the methods and headers you use, and only enable credentials when needed. CORS doesn't stop requests from being sent — protect state-changing endpoints with CSRF defences too.
Frequently Asked Questions
Why test with evil.example?
An unrelated origin reveals whether the server trusts any origin. Test your real frontend origin too, to confirm legitimate requests work.
Why does my browser still show a CORS error?
Check the preflight: if OPTIONS returns an error or lacks Allow-Methods/Allow-Headers for your request, the browser stops before sending it.
What do you do with the domains and URLs I check?
Our server performs the lookup once and returns the result to your browser. We don't store the addresses you check or build a history. Private and internal addresses are blocked.
Related Tools
HTTP Header Checker
View every HTTP response header a URL returns, with explanations and the redirect chain.
Security Headers Checker
Scan any website's HTTP security headers and get an A+ to F grade with fixes.
CSP Evaluator
Analyse a Content-Security-Policy for bypasses and weaknesses — paste it or fetch it from a URL.