Use this little website to test if a URL is setup correctly to work with CORS.
Shareable link: https://cors-test.codehappy.dev/?method=get&origin=https%3A%2F%2Fchatgpt.com&url=https%3A%2F%2Fcdn.oaistatic.com
These are the response headers received when making the request.
access-control-allow-origin: *
access-control-expose-headers: content-length
cache-control: public, max-age=2592000
cf-cache-status: EXPIRED
cf-ray: 9df58b7eb29efad4-CMH
connection: keep-alive
content-length: 223
content-type: application/xml
date: Fri, 20 Mar 2026 14:53:11 GMT
expires: Sun, 19 Apr 2026 14:53:11 GMT
server: cloudflare
set-cookie: __cf_bm=BBO4T_rnIEhsLgn7xNqnKp2HIc35ff0b_LtqgB5Fj78-1774018391-1.0.1.1-OFWg286P5P.wXNK8cfmJOyYOyJGFgQIA.HL7kDwfj4i6eUOMHH49p3JhycI2zdwI52aMFlFERillWYbC95jElEvpJu8AJK.FUBBDLzV43sw; path=/; expires=Fri, 20-Mar-26 15:23:11 GMT; domain=.oaistatic.com; HttpOnly; Secure, _cfuvid=v7Q4G3ajWmVRWxxwbZyHCpCqD0lRieBxeQroMikULBo-1774018391565-0.0.1.1-604800000; path=/; domain=.oaistatic.com; HttpOnly; Secure; SameSite=None
strict-transport-security: max-age=31536000; includeSubDomains; preload
timing-allow-origin: https://chatgpt.com
x-content-type-options: nosniff
x-ms-request-id: d2931932-301e-0091-4c79-b812b6000000
CORS tester was built by @mscccc. The code is available on GitHub. Sponsored by HTML/CSS to Image.