CORS Tester
Test whether an API allows cross-origin requests from the browser — any method, headers and credentials. See if a preflight was needed, what failed, and get the server config to fix it.
How to use
- 1Enter the API URL and method, plus any headers or body.
- 2Press Test CORS — the request is sent by your browser, just like a web app would.
- 3Read the verdict and copy the Express, nginx or Apache config to allow your origin.
Frequently asked questions
Why does it work in curl/Postman but not in my app?
CORS is enforced only by browsers. Servers must explicitly allow a web page's origin with Access-Control-Allow-Origin, and approve preflights for non-simple requests.
What is a preflight?
For methods like PUT/DELETE, custom headers or a JSON Content-Type, the browser first sends an OPTIONS request asking permission. The server must answer it with the right Access-Control-Allow-* headers.
How can it tell CORS apart from a dead server?
After a failed request it sends a second, opaque no-cors request. If that one succeeds, the server is up and the failure was a CORS block.