Use this little website to test if a URL is setup correctly to work with CORS.
Shareable link: https://cors-test.codehappy.dev/?method=get&origin=https%3A%2F%2Fchatgpt.com&url=https%3A%2F%2Fcdn.oaistatic.com
These are the response headers received when making the request.
access-control-allow-origin: *
access-control-expose-headers: content-length
cache-control: public, max-age=2592000
cf-cache-status: MISS
cf-ray: a31fe68d99b4fad4-CMH
connection: close
content-length: 223
content-type: application/xml
date: Fri, 28 Aug 2026 02:31:35 GMT
expires: Sun, 27 Sep 2026 02:31:35 GMT
nel: {"report_to":"cf-nel","success_fraction":0.01,"max_age":604800}
report-to: {"group":"cf-nel","max_age":604800,"endpoints":[{"url":"https://a.nel.cloudflare.com/report/v4?s=GNRZ6BTjPZp93mUodZPCnAVW%2FaEDC8ZXd7cVn9y9Xt%2BGFJpdkzcLyvKcbjfZL0XkQLNl%2BPRBfoOoKLFIxwgh5dQD%2FLnMyOmLn1FtbXbOzeUgCklv8X6ndUSPf1ZKhcljAyNR%2BwPHym6Qsa5kMmGvxnDeo%2FJGE162w0sYrrU7tV4%3D"}]}
server: cloudflare
set-cookie: __cf_bm=JAcjOLDWBJs.W2gp493VUgw8UayOwyRhhe9AYpa0j3U-1787884295.2927988-1.0.1.1-kDkpnWM0krzVq80uJA1JocaOOWaWOYEvlwmoOSQof7BUwIQL8q0S8j8251e_8_Q2o5Uxbsn.CFiTuN9Gl6nZ3HqIxI6MLm2bRP.IQkyZNl9BnGSuDVc3C_rIRG_DIP1F; HttpOnly; Secure; Path=/; Domain=oaistatic.com; Expires=Fri, 28 Aug 2026 03:01:35 GMT, _cfuvid=mNpDCa2Bwo8K0e_9Q4cL2Qo4qW.jHmwa.HF6WCMvlAw-1787884295.2927988-1.0.1.1-eQOpQcfOsYTqJGqyEGeabnDmoh8NEgw4dhmHKvFSYUY; HttpOnly; SameSite=None; Secure; Path=/; Domain=oaistatic.com
strict-transport-security: max-age=31536000; includeSubDomains; preload
timing-allow-origin: https://chatgpt.com
x-content-type-options: nosniff
x-ms-request-id: c39ebcd4-901e-0037-3995-361f56000000
x-ms-request-priority: 3
CORS tester was built by @mscccc. The code is available on GitHub. Sponsored by HTML/CSS to Image.