Search tools

Search for a command to run...

CORS Tester

Test whether an API allows cross-origin requests from the browser — any method, headers and credentials. See if a preflight was needed, what failed, and get the server config to fix it.

How to use

  1. 1Enter the API URL and method, plus any headers or body.
  2. 2Press Test CORS — the request is sent by your browser, just like a web app would.
  3. 3Read the verdict and copy the Express, nginx or Apache config to allow your origin.

Frequently asked questions

Why does it work in curl/Postman but not in my app?

CORS is enforced only by browsers. Servers must explicitly allow a web page's origin with Access-Control-Allow-Origin, and approve preflights for non-simple requests.

What is a preflight?

For methods like PUT/DELETE, custom headers or a JSON Content-Type, the browser first sends an OPTIONS request asking permission. The server must answer it with the right Access-Control-Allow-* headers.

How can it tell CORS apart from a dead server?

After a failed request it sends a second, opaque no-cors request. If that one succeeds, the server is up and the failure was a CORS block.