Network & Testing
CORS Preflight Checker
Evaluate one supplied origin, method and header-name combination using OPTIONS.
Processed on our CPU server.Submitted input is processed for this run and is not stored. This server resolves and visits the supplied public URLs. Query values are sent to the target and redacted in report URLs. No cookies or authorization are sent.
256 KiB limitInput
Result
A useful result starts here.
Paste your input or load an example,
then run the tool.
Supported formats & limitations
- One OPTIONS request; redirects are not followed. Wildcard cannot authorize credentialed requests; Authorization requires an explicit allowed header. No actual method call, credentials or browser preflight cache verification.
- Only public HTTP port 80 / HTTPS port 443. Every DNS answer and redirect is validated, with pinned connections and no ambient credentials/cookies. Private/reserved/metadata addresses, custom ports, URL credentials and fragments are rejected.
- Three-second request deadline, 32 KiB response headers, no decompression, at most three redirects. URL query values are transmitted to the target but redacted in displayed/exported URLs.
- Reports reflect this server runtime at check time. A timeout/auth/rate limit does not prove a dead source. No universal security grade or user-network claim. MCP access and public deployment remain separate tasks.
Execution budget: 10s; output limit: 4096 KiB. Browser worker startup has a separate 3s allowance.