CORS Misconfiguration Tester
Send preflight and credentialed requests from arbitrary origins to see what a malicious site could actually read. Authorization required.
Responsible use
This tool sends requests to a live third-party endpoint. Use it only on systems you own or have explicit written authorization to test. Unauthorized testing may be illegal in your jurisdiction.
Request configuration
Requests are sent from this page's real origin, (unknown).
Browsers won't let a script set the Origin header to anything else, and they hide the literal Access-Control-* header values from JS. This probe reports what the browser actually observed for this origin — it can't simulate an attacker origin like evil.example. For that, proxy the request server-side with a custom Origin header (e.g. curl -H "Origin: https://evil.example" -I <target>).
Confirm authorization above to enable this tool.