Skip to main content

Pentrova is launching soon. Join the waitlist for early access.Join the waitlist

Free tool · CORS checker

Inspect the CORS policy on any endpoint.

Paste any HTTPS endpoint and Pentrova returns a deterministic breakdown of its CORS configuration: allowed origin, credential exposure, methods, exposed headers, and preflight cache. The request runs from your browser and nothing is stored on our servers.

We run checks in your browser. Nothing is stored on our servers.

How the check works

  • Origin + credentials

    We grade the Access-Control-Allow-Origin and Access-Control-Allow-Credentials pair and flag unsafe combinations such as wildcard + credentials.

  • Methods + preflight

    A preflight OPTIONS call reads Allow-Methods, Allow-Headers, Expose-Headers, and Max-Age so you can see the full cross-origin surface area in one view.

  • No persistence

    Submitted URLs are never logged, cached, or shared. Results live only in the current browser session.

Site search

↑↓ navigateEnter openEsc close