Security and networkingChecked through WebDiag API

CORS Header Checker

Enter an API URL and Origin to check CORS response headers without fake browser simulation.

  • ACAO
  • credentials
  • Vary: Origin
Online tool

Try the tool

Enter a URL: WebDiag will run a safe network check and show the result.

CORS

Network check through backend

For HTTP/SEO tools, the URL is sent to the WebDiag API, where SSRF protection, DNS/IP policy, and redirect limits are applied.

Reviewed: 2026-07-17
01

How to use it

  1. 1

    Enter a public resource URL.

  2. 2

    Enter the Origin to test.

  3. 3

    Review ACAO, credentials, and cache variation.

02

What the tool can do

  • Sends a safe request with an Origin header.
  • Checks wildcard + credentials misconfiguration.
  • Flags Vary: Origin for cache correctness.
03

Common use cases

  • Check whether a specific frontend Origin is allowed.
  • Find dangerous wildcard with credentials.
  • Prepare an API for safe CDN/cache behavior.
04

How it works inside

The check is not full browser CORS emulation.

The result is based on one safe HTTP request with the given Origin.

05

Questions and answers

Why is * + credentials bad?

That combination is not a controlled access policy and must not be used for credentialed access.

Does this check OPTIONS preflight?

No. A preflight matrix is a later extension to avoid mixing simple header checks with heavier API testing.