Test CORS configuration for any URL. Debug cross-origin request issues instantly.
Set the Origin header to simulate a cross-origin request from a specific domain.
Browsers stop a web page from reading responses from another domain unless that domain says it is allowed. Cross-Origin Resource Sharing, or CORS, is how a server grants that permission, using response headers. When a front-end app calls an API on a different domain and the console says the request was blocked by CORS policy, the fix is almost always on the API server, not in the front-end code. This checker shows the CORS headers a URL returns, so you can see exactly what it allows.
For anything beyond a simple GET or form post, such as JSON bodies, custom headers, PUT or DELETE, the browser first sends an OPTIONS request asking permission. If the server does not answer it with the right headers and a success status, the real request is never sent. Many CORS errors are really preflight errors: a framework or firewall returning 404 or 401 to OPTIONS.
CORS is enforced only by browsers. It does not stop servers, scripts or tools like curl from calling your API, so it never replaces proper authentication.