Skip to main content

CORS debugger

Paste a browser request and its response headers to understand preflight requirements, CORS blocks and headers JavaScript can read.

Follows the Fetch Standard; browser implementations can differ. Models an ordinary uncached fetch with mode: "cors". Redirects, service workers, streaming uploads, network availability and cookie policy need browser context beyond this check.

These tools run entirely in your browser. Nothing you paste or drop is uploaded, stored, or sent to analytics.

Try a scenario

The scheme, host and port determine the origin. The literal null models an opaque origin.

An absolute HTTP(S) URL. This tool never contacts it.

Use the method passed to fetch, such as GET, POST or PATCH.

Use the credentials option passed to fetch. Cookie delivery also depends on browser and cookie policy.

One Header: value per line. Include headers your code sets, such as Content-Type or Authorization; omit browser-managed headers such as Origin and Cookie.

Paste the OPTIONS status line and headers separately from the final response. Bare headers leave the preflight status unknown.

Paste one final response, including its status if available. Informational responses are supported; multiple final responses stay ambiguous.

Header names separated by commas or newlines, such as X-Payment-Response. Leave blank to skip exposure checks.

Limits: 64 KiB per header block, 256 headers, 16 response blocks and 2,048 lines. Ctrl/⌘ + Enter checks immediately.

Choose a scenario or enter an origin and request URL to inspect the CORS gates.