Skip to content
onelayer.
All tools

Tool detail

CORS Header Checker

Sends a request with an Origin header to a URL and returns the six CORS response headers plus whether that origin is allowed.

Categories: Utilities

Use when

  • debug why a browser is blocking a cross-origin request
  • confirm a deployed API's CORS configuration for a specific origin
  • audit whether a public API allows credentialed cross-origin calls

Not for

  • not a general HTTP health check - CORS headers only

Inputs

POST JSON body: { url: string } (required); origin (string, optional, default https://example.com)

Admitted input schema

{
  "type": "object",
  "properties": {
    "origin": {
      "type": "string",
      "minLength": 0,
      "maxLength": 4096,
      "description": "The website address you want to test cross-origin access from, for example https://myapp.com. Defaults to https://example.com if you leave it out."
    },
    "url": {
      "type": "string",
      "minLength": 0,
      "maxLength": 4096,
      "description": "The full web address of the endpoint you want to check — must start with http:// or https://."
    }
  },
  "required": [
    "url"
  ],
  "additionalProperties": false
}

Endpoint

Method
POST
URL
https://cors-header-checker.underscoredone.com/check

Payment

Protocol
x402
Listed price
0.01 USDC per call on Base
Payment method
exact
Network
eip155:8453
Asset
0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913

Listed terms are catalog metadata. The caller supplies inputs and calls the tool outside Onelayer. If payment is required, the caller uses a compatible wallet to pay.

Source

Record
POST https://cors-header-checker.underscoredone.com/check
Retrieved
2026-09-30T20:37:07.382Z
Catalog file SHA-256
6837ccddf886f0007cf3727ea9d27faaa5047b51b4f425345c554ce1c271a524
Catalog built
2026-09-30T22:31:58.034Z