CORS Checker
Test any URL for CORS (Cross-Origin Resource Sharing) headers. The tool sends a preflight OPTIONS request and a regular GET request, then reports which origins, methods, and headers are allowed. Spot misconfigurations and security issues.
URL to check for CORS headers
advanced options
Origin to send in the preflight request
returns
- data.cors_enabled
- True when the server sends Access-Control-Allow-Origin.
- data.headers
- The CORS headers the server sent, null when missing.
- data.analysis
- Allowed origins, methods and headers, plus security notes.
- data.preflight_status
- HTTP status of the OPTIONS preflight request.
Fill in the fields and send a request. The response lands here.
Run it from your code
A temporary key takes one request and lasts seven days at 20 calls a day. Register and it becomes 75 a day, still free.
$ curl -s "https://apixies.io/api/v1/check-cors?url=https://api.github.com" \ -H "X-API-Key: $APIXIES_KEY" | jq '.data.cors_enabled' true
questions
What is a CORS preflight request?
Browsers send an OPTIONS request before certain cross-origin requests to check if the server allows them. This is the "preflight" check. The tool simulates this to see how the server responds.
Why is wildcard origin with credentials a problem?
Browsers block requests that use Access-Control-Allow-Origin: * together with Access-Control-Allow-Credentials: true. It's a security risk and a misconfiguration that needs fixing.
What if the server doesn't respond to OPTIONS?
Some servers don't handle preflight requests. The tool also checks the regular GET response for CORS headers and reports what it finds either way.