CORS Tester

Test whether a URL’s CORS headers let a browser on another origin call it — preflight and actual request.

How do I test CORS on my API?

Enter the API URL, your website’s origin and the method. The tester sends a preflight OPTIONS request and a normal request with that Origin header and checks Access-Control-Allow-Origin, Allow-Methods, Allow-Headers, credentials and Vary, then tells you whether a browser would allow or block the call.

Typical fixes

  • Return Access-Control-Allow-Origin: https://your-site.com (or * for public data).
  • Answer OPTIONS preflights with 204 and the allowed methods and headers.
  • With cookies, send Access-Control-Allow-Credentials: true and a specific origin, never *.

Frequently asked questions

Why does Postman work but my browser does not?

CORS is enforced only by browsers; servers and tools like Postman ignore it.

What is a preflight?

An automatic OPTIONS request browsers send before non-simple requests, e.g. with JSON or custom headers.

Is it free?

Yes.