← All tools

CORS Simulator: Preflight, Origins & Credentials

Reason through supplied CORS request and response settings locally, including preflight and wildcard credential restrictions, without making network requests.

Enabling local controls…

1. Offline request conditions

Memory only; no request or storage. Total limit: 1 MiB UTF-8, 200 lines per block, 8,192 characters per line. Complete header values are needed for safelist classification; values are masked by default and reports include names only.

Authorization is a separate request header and does not automatically select include. Origin has no path or trailing slash.

Scope: Fetch CORS safelists, ordinary cross-origin preflight and actual response. Assumes no preflight cache, redirects, streaming body, forced preflight or private-network extensions; excludes CSP, TLS, Cookie SameSite and network failures. HTTP success does not prove JS readability. CORS is not authentication or a request firewall.

Rules: WHATWG Fetch

2. Browser reading simulation

Enter conditions or load a sample, then simulate.

How to use this tool

Enter the requesting origin, target and method, supplied headers and credential mode. Compare the preflight and final-response decisions and correct the indicated policy mismatch.

When not to use it

A simulated pass does not verify an endpoint. CORS governs browser response sharing, not authentication or CSRF protection; a blocked read does not prove a request had no server-side effect.

Read the guide →