CORS Response Simulator

CORS Response Simulator

Enter a proposed browser request and the two possible server responses.

Local Fetch CORS model only; no live request or security certification. Redirects, preflight cache, private-network checks and browser-specific behavior are outside scope.

1. Browser request

One Name: value per line. Origin and Cookie are browser-controlled; enter only author headers. Header names ignore case. Fetch uppercases six common methods before exact method comparison.

2. OPTIONS response

Enter the server's proposed Access-Control-Allow-Origin, -Credentials, -Methods and -Headers values. These are checked only if a preflight is required.

3. Actual response

A 403 can still pass CORS and be readable. CORS does not decide whether the HTTP request succeeded.

Edit a field or load an example, then run the simulation.

Normative source

Comments & questions

CORS Response Simulator

Model an ordinary browser CORS exchange with the headers you supply. See whether an OPTIONS preflight is needed, whether the actual request is sent and whether script can read the final response.

Key features

  • Compare the script origin with the target URL's scheme, host and port
  • Derive a preflight from method and CORS-unsafe author request headers
  • Test OPTIONS status, allowed origin, credentials, methods and headers separately
  • Distinguish a blocked preflight from an actual request whose response is unreadable
  • Load success, wildcard-with-credentials and simple GET examples without contacting a server

How to use

  1. Enter the script origin, full target URL, method, credentials mode and author request headers.
  2. Enter the proposed OPTIONS response status and Access-Control-Allow-* headers.
  3. Enter the proposed actual response status and Access-Control-Allow-* headers.
  4. Run the simulation and read the step-by-step reason for each stage.

Use cases

  • Understand why a credentialed fetch fails with Access-Control-Allow-Origin: *.
  • Check whether a JSON POST requires OPTIONS and which names appear in Access-Control-Request-Headers.
  • Find a missing explicit Authorization allowance or method spelling mismatch.
  • Show why a server's 403 response may still be readable while a failed preflight sends no actual request.

Frequently asked questions

Does this send an OPTIONS or fetch request?

No. It evaluates only the text entered in your browser. Network errors, redirects, cache entries, private-network access, service workers and browser extensions are outside this model. Confirm the final behavior in a real browser and server logs.

Why does Access-Control-Allow-Origin: * fail with credentials?

Fetch's CORS check accepts the wildcard only when credentials mode is not include. With include, the response must name the serialized request origin and return Access-Control-Allow-Credentials: true on both a needed preflight and the actual response.

Are method and header names compared with the same case rules?

No. Fetch first uppercases DELETE, GET, HEAD, OPTIONS, POST and PUT. Access-Control-Allow-Methods then uses the effective method's exact spelling, while allowed request header names are compared without case. Extension methods such as PATCH retain their entered case.

If the tool says blocked, did the server receive the request?

A failed preflight prevents the actual request. Without a preflight, or after a successful one, the actual request can reach the server even if its response fails the final CORS check. CORS is a browser read-access protocol, not a server authorization rule.

What is intentionally not modeled?

This bounded profile handles HTTP(S) CORS-mode requests with ordinary methods and ASCII author headers. It does not model redirects, 304/407 responses, preflight cache, forced preflight for streaming bodies, request body, response-header exposure, private-network access, mixed content or server authentication. Complex MIME parameters can be conservatively treated as unsafe.

Privacy

Header text stays in this browser tab's memory. The simulator sends no requests, uploads nothing and keeps no automatic copy. Avoid pasting real credentials or secrets; do not share screenshots containing private headers.

Related Tools

Curl Request WorkbenchHTTP Status Code LookupAPI Mock SandboxWasm Module InspectorHreflang Matrix CheckerAST Query PlaygroundContainer Build GraphDependency Graph ExplorerSemver Range LabCron Schedule AuditorPatch Review WorkbenchSource Map ExplorerLocalization Catalog AuditorStructured Data ReviewerHTTP Archive AnalyzerWebhook Signature LabProtobuf Schema WorkbenchGraphQL Schema LabAvro Schema EvolutionLocal SQL WorkbenchSchema Form BuilderMesh Repair WorkbenchPipe Network LabRobot Arm Kinematics LabThermal Network LabBeam Response LabGear Train DesignerTolerance Stackup LabSensor Calibration FitPCB Stackup PlannerDigital Filter DesignerNetwork Reachability MapSun Shadow MapGPS Error SimulatorDigital Logic SimulatorAnalog Circuit LabMechanism Linkage LabAnalysis Mesh GeneratorOpenAPI Contract InspectorDatabase Migration PlannerDimensional Equation CheckerTruss Force LabBoolean Minimization LabControl Response LabQueueing Simulation LabGeofence Event SimulatorCoordinate Reference LabSurvey Traverse LabRaster Classification LabChoropleth Design LabMap Print ComposerRaster Reprojection LabElevation Contour MakerTerrain Viewshed LabWatershed DelineatorMap Tile PackagerText File Encoding WorkbenchFilesystem Portability AuditorSBOM License ExplorerFile Signature Auditornpm Lockfile Conflict ResolverSource Secret AuditorOffline Web Package BuilderCertificate Chain InspectorTorrent Metainfo InspectorChunked File PackagerEncrypted File VaultDuplicate File FinderArchive WorkbenchDesign Token ManagerSpacing Token DesignerResponsive Type SystemPackaging Dieline DesignerSVG Icon Sprite PackerFlex Layout PlaygroundCSS Grid PlaygroundRegex Equivalence LabMarkdown Repository AuditorLog Template MinerResponsive Layout AuditorEmail Template PreviewInternal Link GraphState Machine TesterPetri Net SimulatorGit History VisualizerBinary Protocol DesignerHex File EditorBinary Patch WorkbenchFile Signature WorkbenchSchema Column MapperEvent Log SessionizerER Diagram DesignerTime Series Gap AuditorStratified Data SplitterData Lineage DesignerDecision Tree LabData Anonymization WorkbenchData Expectation RunnerJSON Schema ValidatorBasket Pattern AnalyzerRobots Policy TesterSEO HTML AuditorAccessibility Structure AuditorSyndication Feed WorkbenchIndexNow Payload BuilderCrawl Log AnalyzerCSP Policy WorkbenchSearch Performance AnalyzerCSV Formula Risk AuditorCache Header LabCookie Policy InspectorWeb Vitals Trace LabSitemap Health AuditorBatch File RenamerFile Manifest VerifierFolder Space MapFolder Difference ReviewerRoute Order OptimizerGeoJSON Map EditorPolygon Overlay LabCartographic Label PlacerSpatial Table JoinGeoJSON Topology AuditorGPX Track AnalyzerTrack Privacy RedactorCSV Table JoinCSV Pivot WorkbenchScientific Data ProfilerTabular Cleaning WorkbenchRecord ReconciliationData Dictionary BuilderCanonical Graph AuditorRedirect Plan TesterHTTP response and ping reference testBrowser and System InformationJSON ↔ YAML ConverterXML ↔ JSON ConverterHTML FormatterJavaScript MinifierMock Data Generator.gitignore GeneratorLicense GeneratorUser-Agent ParserPassword Strength CheckerCode to ImageXML FormatterMIME Type LookupJS & SQL String EscapeCSS Box Shadow GeneratorCSS Gradient GeneratorIndent ConverterNumber Base ConverterUnicode Escape ConverterUnicode InspectorJSON Structure DiffMarkdown Table GeneratorBase64 EncoderJSON FormatterURL EncoderSQL FormatterCron Expression GeneratorRegex TesterUUID GeneratorHash GeneratorTimestamp ConverterJWT DecoderHTML Entity ConverterMarkdown PreviewCSS MinifierMeta Tag GeneratorJSON ↔ CSVCase ConverterImage to Base64
Explore all Dev Tools tools →Image/Media →Text/Convert →Life/Fun →