Security

Cors Scanner

Work out why a CORS request is blocked and which response header the server is missing.

Last reviewed by the Radiatus Cloud team

CORS Misconfiguration Scanner

Paste HTTP response headers to detect dangerous Cross-Origin Resource Sharing (CORS) configurations.

Need this handled by experts?

Radiatus runs VAPT, managed SOC & security engineering for regulated teams.

Book a free security consult

CORS is enforced by the browser, not the server

The request usually reaches the server and the server usually responds normally. The browser then inspects the response headers, finds the origin is not permitted, and refuses to hand the response to JavaScript. This is why a request that fails in the browser succeeds from curl or Postman, and why server logs show a perfectly ordinary 200 while the console shows an error. Nothing is broken on the server; the server simply has not granted permission.

The same-origin rule is stricter than it looks

Origin means scheme, host and port together. https://example.com and http://example.com are different origins. So are example.com and www.example.com, and localhost:3000 and localhost:8080. A great many CORS problems in development are a port difference nobody registered as an origin change.

Preflight requests and what triggers them

Simple requests go straight out. Anything else triggers an OPTIONS preflight first, and the browser only sends the real request if the preflight approves it. Custom headers such as Authorization or a Content-Type of application/json are the usual triggers. A server that handles GET and POST correctly but returns 404 or 405 for OPTIONS will fail every preflighted request, and this is the most common CORS misconfiguration by a wide margin.

Credentials change the rules entirely

When a request carries cookies or authentication headers, the server must return Access-Control-Allow-Credentials: true, and Access-Control-Allow-Origin may not be the wildcard. It must name the exact origin, which usually means echoing the request's Origin header back after validating it against an allow-list. Wildcard plus credentials is rejected by every browser, and the resulting error message rarely says so plainly.

Wildcards are a decision, not a default

Access-Control-Allow-Origin: * makes an endpoint readable by script on any site. That is correct for a public API and wrong for anything authenticated or internal. Echoing back whatever Origin arrives without checking it against a list is functionally the same as a wildcard while looking like a restriction, and it is a recurring finding in security reviews.

Errors JavaScript cannot see

A cross-origin response exposes only a short list of headers to script unless Access-Control-Expose-Headers names more. A failed request also gives JavaScript almost no detail, deliberately, so the browser console and the network tab are the only places the real cause appears. Reading the console message rather than the caught exception is usually the fastest route to the answer.

Related tools

  • Password Strength Checker — Measure password strength by entropy and pattern analysis rather than character-class rules. Checked entirely in your browser.
  • Password Generator — Generate strong random passwords and passphrases in your browser using the Web Crypto API. Nothing is transmitted, logged or stored.
  • Hash Generator — Generate MD5, SHA-1, SHA-256 and SHA-512 hashes in your browser. Compare checksums and verify file integrity with nothing uploaded to a server.
  • Base64 Encoder/Decoder — Encode and decode Base64 in your browser, including URL-safe Base64 and UTF-8 text. Handles files and data URIs locally with nothing uploaded.

Frequently Asked Questions

Why does my request work in Postman but not the browser?

Because CORS is enforced by the browser, not the server. The request succeeds and the server logs a normal 200; the browser then refuses to hand the response to JavaScript.

What counts as a different origin?

Scheme, host and port together. https and http differ, example.com and www.example.com differ, and localhost:3000 and localhost:8080 differ β€” the last catches most development setups.

What is a preflight request?

An OPTIONS request the browser sends first for anything beyond a simple request, typically triggered by custom headers or a JSON content type. A server returning 404 or 405 for OPTIONS fails every such request.

Why does my CORS config fail with cookies?

Because credentialed requests require Access-Control-Allow-Credentials: true and forbid the wildcard origin. The server must name the exact origin, validated against an allow-list.

Is Access-Control-Allow-Origin: * safe?

Only for genuinely public data. It lets script on any site read the response, which is wrong for anything authenticated. Echoing back the Origin unchecked is equivalent while looking restrictive.

Privacy & Security

Processed locally.

Data: None
Client-side-Side
Active
v1.0

About This Tool

This tool runs entirely in your browser. No data is sent to any server, ensuring complete privacy. Simply use the interface above to get started β€” no registration or login required.

Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.