Enter a URL to check whether it allows cross-origin requests from a given Origin — simulates both the actual request and the preflight (OPTIONS). Up to 20 checks/hour per visitor.
curl -sS "https://devops.majbase.com/cors-checker/api?url=https://api.example.com/data&origin=https://myapp.example"
Returns {"url", "tested_origin", "status_code", "cors_enabled", "allow_origin", "origin_allowed", "allow_credentials", "expose_headers", "preflight", "warnings"}, or {"error": "..."}. Rate limited to 20 checks/hour per source IP; refuses to connect to a hostname that resolves to a private/internal address.
Want an AI agent (Claude Code, claude.ai, or anything else that supports the Agent Skills format) to use this tool for you on request? Download the skill below and add it:
~/.claude/skills/cors-checker/SKILL.md