Free tool · No sign-up · Server-assisted
CORS Tester
Send a preflight and a real request to any endpoint and read back exactly what it allows: which origins, which methods, which headers, and whether credentials are permitted. Spells out the common misconfigurations — a wildcard origin paired with credentials, a reflected Origin that trusts everyone — rather than leaving you to infer them.
Server-assisted · we send a preflight from a random test origin to see what the endpoint allows
Method & assumptions
- This is a server-assisted tool. It sends a request from a deliberately random Origin, so an endpoint that echoes that Origin back is genuinely reflecting it, not matching an allowlist that happens to include you.
- Only the URL you enter is sent, and only to our server, which probes it once. Nothing is stored.
- A wildcard origin combined with credentials is rejected by browsers — it is flagged as a misconfiguration, not an open door, because credentialed requests will simply fail.
- Reflecting any origin while allowing credentials is the dangerous case: it lets any site make authenticated requests as your users.
Other tools
More on the bench
- 01
Supabase Security Auditor
Point it at your project, find the holes. - 02
JWT Decoder
Paste a token, read what is inside. - 03
Secret & .env Scanner
Paste code or a .env, catch the leaked keys. - 04
Security Headers Scanner
Enter a URL, grade its headers. - 05
Base64 Encode / Decode
Text or files, both directions. - 06
URL Encode / Decode
Percent-encoding, both directions. - 07
JSON Formatter
Validate, pretty-print, or minify. - 08
UUID Generator
v4 and v7, one or a thousand.
Software engineering
We write the software
behind tools like these
Anyone staring at a CORS error, or checking their own API is not open to every origin on the web.
- Free diagnostics
- Same-day across most of the metro
- Named technicians
- No fix, no labour charge