Skip to content
GET /api/v1/check-cors

CORS Checker

Test any URL for CORS (Cross-Origin Resource Sharing) headers. The tool sends a preflight OPTIONS request and a regular GET request, then reports which origins, methods, and headers are allowed. Spot misconfigurations and security issues.

url required

URL to check for CORS headers

advanced options
string

Origin to send in the preflight request

X-Sandbox-Remaining: - get an api key

returns

data.cors_enabled
True when the server sends Access-Control-Allow-Origin.
data.headers
The CORS headers the server sent, null when missing.
data.analysis
Allowed origins, methods and headers, plus security notes.
data.preflight_status
HTTP status of the OPTIONS preflight request.
response awaiting request sending
Fill in the fields and send a request. The response lands here.

Run it from your code

A temporary key takes one request and lasts seven days at 20 calls a day. Register and it becomes 75 a day, still free.

$ curl -s "https://apixies.io/api/v1/check-cors?url=https://api.github.com" \
    -H "X-API-Key: $APIXIES_KEY" | jq '.data.cors_enabled'

true

questions

What is a CORS preflight request?

Browsers send an OPTIONS request before certain cross-origin requests to check if the server allows them. This is the "preflight" check. The tool simulates this to see how the server responds.

Why is wildcard origin with credentials a problem?

Browsers block requests that use Access-Control-Allow-Origin: * together with Access-Control-Allow-Credentials: true. It's a security risk and a misconfiguration that needs fixing.

What if the server doesn't respond to OPTIONS?

Some servers don't handle preflight requests. The tool also checks the regular GET response for CORS headers and reports what it finds either way.

cookies

We use analytics cookies to see how the site gets used. Nothing loads until you accept. Privacy policy