Tools
CORS tester
Send a live cross-origin request from this browser tab and see exactly what a page on this origin may read. The request goes from your browser straight to the URL you enter; nothing is proxied, stored, or logged.
What the live request proves
The header checker answers a static question about pasted headers. The tester answers the live one: can a page on this origin read a response from that URL right now. It sends a GET or HEAD from this browser tab with no credentials, then reports the real status, the response headers the browser exposes to JavaScript, or an honest refusal.
A refusal stays deliberately vague. Browsers hand JavaScript the same TypeError for a CORS rejection and for a network failure, and this tool will not guess between the two. For a static read of headers you already captured, use the CORS header checker.
When you cannot fix the server
If the API is yours, the fix lives on your server: return the right Access-Control-Allow-Origin value and the tester reports a readable response. If the API belongs to someone else, no browser setting or client-side trick can change their policy. The response has to travel through a path that adds permission.
That path is either a small backend you own or a managed proxy. cors.dev runs one: keyless GET and HEAD requests to any public host through https://proxy.cors.dev/, and a free account adds Connections, publishable keys, and an activity view. Compare the proxy and backend options.