OneFirewall Alliance

CORS Policy Tester

Test Cross-Origin Resource Sharing configuration — fire preflight and simple requests and inspect headers

Enter an endpoint and the tester sends simple and preflight (OPTIONS) requests, then shows the Access-Control-* headers returned. Use it to confirm which origins, methods and headers an API allows and to spot overly permissive wildcard policies. More free security tools.

CORS policies are enforced by browsers. This tool fires real preflight and direct requests from your browser, plus uses a proxy cascade to inspect server headers when direct CORS requests are blocked.

Need to audit and harden your API security posture?

If you like this tool, Speak with OneFirewall