Search 93+ free tools… (e.g. json, vpn, password) ⌘K
Link Tools Dereferer Hide Referrer Link URL Shortener Affiliate Cloaker PayPal Links PayPal DonationPayPal Links Privacy Tools Password Generator Cloudflare Resolver My Referrer Torrent Tools Magnet → Torrent Torrent → Magnet Torrent Editor Pirate Bay Proxies Movierulz Proxies ExtraTorrent Proxies Dev Tools Base64 Encoder Hash Generator HTTP Headers Disposable Email Checker Company Blog About Us Contact Anonymize Free
Dev Tool

CORS Headers Checker

Test CORS configuration for any URL. Debug cross-origin request issues instantly.

Set the Origin header to simulate a cross-origin request from a specific domain.

🔍
What CORS checks
Tests Access-Control-Allow-Origin, methods, credentials, preflight OPTIONS requests and Vary headers.
🚫
Common CORS errors
Missing CORS headers, wrong origin, blocked methods, or credentials not allowed — all diagnosed instantly.
⚡
Server-side testing
Our tool makes the request from our server so it bypasses browser CORS restrictions — seeing the raw headers.

Frequently Asked Questions

What is CORS and why does it matter?
Cross-Origin Resource Sharing (CORS) is a browser security mechanism that controls which external domains can make requests to your API or server. Misconfigured CORS headers can either block legitimate requests from your own frontend or inadvertently allow unauthorised third-party sites to access your data.
What does the CORS checker test?
The checker sends a preflight OPTIONS request to your URL and inspects the response headers including Access-Control-Allow-Origin, Access-Control-Allow-Methods, and Access-Control-Allow-Headers. It reports whether your server's CORS policy is correctly configured for cross-origin requests.
My CORS check is failing — how do I fix it?
Add the correct Access-Control-Allow-Origin header to your server's response. For specific origins, set the header to the exact domain. Also ensure your server handles OPTIONS preflight requests and returns a 200 status with the correct CORS headers.
What is CORS?
Cross-Origin Resource Sharing (CORS) is a browser security feature that restricts web pages from making requests to a different domain than the one that served the page. APIs must include CORS headers to allow cross-origin requests from browsers.
Why does my API work in Postman but not in the browser?
Postman does not enforce CORS — it sends requests directly. Browsers enforce CORS for security. If your API returns the correct CORS headers, browsers will allow the request. This tool tests what headers your server actually returns.
What is a CORS preflight request?
Before sending certain cross-origin requests (non-simple requests), browsers first send an OPTIONS request to check if the server allows the operation. The server must respond with the appropriate Access-Control-Allow-* headers.
🛡️
Your IP address and DNS queries are visible to your ISP. Protect your privacy with a trusted VPN — tested and recommended by Anonymiz.
See Recommended VPNs →

What CORS is and why requests fail

Browsers stop a web page from reading responses from another domain unless that domain says it is allowed. Cross-Origin Resource Sharing, or CORS, is how a server grants that permission, using response headers. When a front-end app calls an API on a different domain and the console says the request was blocked by CORS policy, the fix is almost always on the API server, not in the front-end code. This checker shows the CORS headers a URL returns, so you can see exactly what it allows.

The headers that matter

Preflight requests

For anything beyond a simple GET or form post, such as JSON bodies, custom headers, PUT or DELETE, the browser first sends an OPTIONS request asking permission. If the server does not answer it with the right headers and a success status, the real request is never sent. Many CORS errors are really preflight errors: a framework or firewall returning 404 or 401 to OPTIONS.

Security mistakes to avoid

CORS is enforced only by browsers. It does not stop servers, scripts or tools like curl from calling your API, so it never replaces proper authentication.

Related Tools

📋
JSON Formatter
Format and validate JSON
📦
Base64 Encoder
Encode and decode Base64
🔏
Hash Generator
Generate MD5, SHA-256 hashes
🔍
Regex Tester
Test regular expressions
🔀
Diff Checker
Compare two texts
🔓
JWT Decoder
Decode JWT tokens
Done!