Security · cross-origin requests
CORS preflight.
Describe the request, paste the server's response headers, and see the decision a browser would make and the exact check that fails. Nothing is fetched or uploaded.
Request and response
Browser decision
Run the check to see each step.
What this checks
- Simple-request test: safelisted method and headers
- Content-Type essence, 128-byte and 1024-byte header limits
- Access-Control-Allow-Origin exact match, * with credentials
- Allow-Credentials, Allow-Methods, Allow-Headers, Authorization
- Preflight status and Access-Control-Max-Age (default 5 s)
Scope: this replays the Fetch Standard algorithm on the headers you paste. It does not contact your server, cannot see what a proxy or CDN changes in transit, and browsers add their own caps and extra rules (for example private-network access). Confirm with a real request in browser DevTools.