Tools

CORS header checker

Paste raw response headers from the DevTools Network tab to evaluate access permissions locally. The parser runs entirely in your browser session and sends no header text to any external server.

Request profileTest a live URL
Try:

Interpreting checker severities

A blocker indicates a definitive failure that guarantees browser rejection, such as a missing Access-Control-Allow-Origin header. An OK status confirms that the submitted headers allow data reading, although live network layers can still alter traffic. Informational warnings flag incomplete input, where evaluating permissions requires preflight headers or request parameters.

What local header inspection cannot detect

  • DevTools captures reflect only the specific execution you copied, while client code might send different methods, credentials, or custom headers in production.
  • CDNs and caching layers frequently strip or vary Access-Control-Allow-Origin headers based on the presence of the Vary: Origin header.
  • Content Security Policy directives on the calling page can terminate requests at the browser network layer before CORS evaluation ever runs.
  • HTTP redirects cause preflight OPTIONS requests to fail automatically under the Fetch specification, regardless of the target headers.

For step-by-step troubleshooting across the whole network lifecycle, work the diagnosis guide.

Want the live answer instead of a static one? The CORS tester sends a real cross-origin request from this browser and reports what the page may read.