DevToolBoxFREE
BlogAdvertise

Penguji CORS

Uji header CORS untuk URL apa pun. Periksa Access-Control-Allow-Origin, metode, dan header.

Penguji CORS Online Gratis

Masukkan URL dan origin untuk menguji header CORS langsung dari browser.

Cara menguji header CORS

  1. Masukkan URL untuk diuji
  2. Atur header Origin
  3. Pilih metode HTTP
  4. Klik "Uji CORS"

Fitur

  • Uji URL apa pun untuk CORS
  • Kirim permintaan preflight OPTIONS
  • Lihat Access-Control-Allow-Origin
  • Periksa dukungan credentials
  • Pengujian CORS berbasis browser

Pertanyaan yang sering diajukan

Apa itu CORS?
CORS adalah mekanisme keamanan yang memungkinkan halaman web meminta sumber daya dari domain lain.
Apa itu permintaan preflight?
Permintaan OPTIONS yang dikirim browser sebelum permintaan cross-origin tertentu.
Apa arti Access-Control-Allow-Origin?
Header ini menentukan origin mana yang diizinkan mengakses sumber daya.
Mengapa permintaan CORS saya diblokir?
Permintaan diblokir ketika server tidak menyertakan header Access-Control-Allow-Origin.
Bisakah saya menguji CORS dari browser?
Ya. Alat ini mengirim permintaan langsung dari browser Anda.

Alat terkait

๐Ÿ’ฌ User Feedback

Have suggestions or found a bug? Leave a message and we'll get back to you.
0/2000

Nilai alat ini

3.8 / 5 ยท 40 penilaian

Stay Updated

Get weekly dev tips and new tool announcements.

No spam. Unsubscribe anytime.

Enjoy these free tools?

How to Use

  1. Enter the API endpoint URL to test
  2. Select HTTP method and add headers if needed
  3. Click Test to send the CORS preflight request
  4. Review the CORS headers in the response

Common Use Cases

  • Debugging CORS errors in APIs
  • Verifying server CORS configuration
  • Testing preflight request handling
  • Checking allowed origins and methods

Frequently Asked Questions

What is CORS?
CORS (Cross-Origin Resource Sharing) is a security mechanism that controls how web pages can request resources from a different domain.
Why am I getting CORS errors?
The server must include proper Access-Control-Allow-* headers. Without these, browsers block cross-origin requests for security.
Can I fix CORS on the client side?
No. CORS must be configured on the server. Client-side workarounds like JSONP are outdated and insecure.

This site uses cookies for analytics and to display ads. By continuing to browse, you agree. Privacy Policy