CORS Misconfiguration Tester

Send preflight and credentialed requests from arbitrary origins to see what a malicious site could actually read. Authorization required.

Pro

Responsible use

This tool sends requests to a live third-party endpoint. Use it only on systems you own or have explicit written authorization to test. Unauthorized testing may be illegal in your jurisdiction.

Request configuration

Requests are sent from this page's real origin, (unknown).

Browsers won't let a script set the Origin header to anything else, and they hide the literal Access-Control-* header values from JS. This probe reports what the browser actually observed for this origin — it can't simulate an attacker origin like evil.example. For that, proxy the request server-side with a custom Origin header (e.g. curl -H "Origin: https://evil.example" -I <target>).

Confirm authorization above to enable this tool.

Probe results

Configure a target, then run the probe.

Related tools