CORS Simulator: Preflight, Origins & Credentials
Reason through supplied CORS request and response settings locally, including preflight and wildcard credential restrictions, without making network requests.
Enabling local controls…
1. Offline request conditions
Memory only; no request or storage. Total limit: 1 MiB UTF-8, 200 lines per block, 8,192 characters per line. Complete header values are needed for safelist classification; values are masked by default and reports include names only.
Authorization is a separate request header and does not automatically select include. Origin has no path or trailing slash.
Scope: Fetch CORS safelists, ordinary cross-origin preflight and actual response. Assumes no preflight cache, redirects, streaming body, forced preflight or private-network extensions; excludes CSP, TLS, Cookie SameSite and network failures. HTTP success does not prove JS readability. CORS is not authentication or a request firewall.
Rules: WHATWG Fetch2. Browser reading simulation
Enter conditions or load a sample, then simulate.
How to use this tool
Enter the requesting origin, target and method, supplied headers and credential mode. Compare the preflight and final-response decisions and correct the indicated policy mismatch.
When not to use it
A simulated pass does not verify an endpoint. CORS governs browser response sharing, not authentication or CSRF protection; a blocked read does not prove a request had no server-side effect.
Read the guide →