CORS Tester

Use this little website to test if a URL is setup correctly to work with CORS.




If your CORS setup is not using a wildcard then this should be a domain that matches your AllowedOrigins


Shareable link:

Results

This URL will not work correctly with CORS.

What's wrong?

It does not have the access-control-allow-origin header set to *. Without this header, requests from other domains cannot be made to it via a users browser.

How to fix it?

If you have access to the server for the URL, you'll need to modify it to add the access-control-allow-origin header. If you do not have access, you'll need to upload the file somewhere else.

Headers

These are the response headers received when making the request.

accept-ranges: bytes
alt-svc: h3=":443"; ma=2592000
cache-control: public, max-age=0
cf-cache-status: DYNAMIC
cf-ray: 9bfc88c9b60110ec-ORD
connection: keep-alive
content-type: text/html; charset=UTF-8
date: Sun, 18 Jan 2026 07:56:11 GMT
last-modified: Tue, 13 Jan 2026 15:25:36 GMT
onion-location: http://silentlnit5ryavvfz5vw7s4qg62jujd666lnc4tg2chj64zuwuqtvqd.onion/
server: cloudflare
transfer-encoding: chunked
via: 1.1 Caddy
x-powered-by: Express
  

CORS tester was built by @mscccc. The code is available on GitHub. Sponsored by HTML/CSS to Image.