ToolAssay

Send exactly one bounded non-credentialed browser-style CORS OPTIONS preflight t

Send exactly one bounded non-credentialed browser-style CORS OPTIONS preflight to the supplied public URL and normalize the observed Access-Control-Allow-* response into origin, method and header decisions. Redirects are not followed, so the result describes the exact resource URL. Forest does not send cookies or Authorization, invoke the requested resource afterward, run JavaScript, or guarantee browser/runtime success beyond the observed response. Base mainnet USDC

Not tested: has real-world effectsour last check, 2026-10-10
0 of 0checks answered this week
n/amedian answer time
$0.002listed price per call
n/aprice it asked us

Paid test badge: not yet. The checks above are free: we call the tool without paying and read the payment request it sends back. The Verified badge needs paid calls whose answers match the promised output, and nobody can buy a badge.

Endpoint

POST https://http--forest-gas-station-mainnet--lcjl27p8lmjs.code.run/cors/preflight

CategoryCode and developer
Provider hosthttp--forest-gas-station-mainnet--lcjl27p8lmjs.code.run
Networkseip155:8453
Payment schemesexact
Self-reported calls, 30 days2 from 2 payers (the provider's figure, not ours)

Our checks, last 30 days

We never call tools that send, buy, move money or file anything, not even without paying.

Example input (from the provider)

{
  "body": {
    "origin": "https://forestfactory.dev",
    "requested_headers": [
      "content-type",
      "x-request-id"
    ],
    "requested_method": "POST",
    "url": "https://http--forest-gas-station-mainnet--lcjl27p8lmjs.code.run/fixtures/cors"
  },
  "bodyType": "json",
  "method": "POST",
  "type": "http"
}

Promised output schema (from the provider)

{
  "$schema": "https://json-schema.org/draft/2020-12/schema",
  "properties": {
    "input": {
      "additionalProperties": false,
      "properties": {
        "body": {
          "additionalProperties": false,
          "properties": {
            "origin": {
              "description": "Public origin value used to scope this lookup.",
              "maxLength": 2048,
              "minLength": 1,
              "pattern": "^https?://",
              "type": "string"
            },
            "requested_headers": {
              "description": "Public requested headers value used to scope this lookup.",
              "items": {
                "maxLength": 128,
                "minLength": 1,
                "type": "string"
              },
              "maxItems": 20,
              "type": "array"
            },
            "requested_method": {
              "description": "Public requested method value used to scope this lookup.",
              "maxLength": 32,
              "minLength": 1,
              "type": "string"
            },
            "url": {
              "description": "Public HTTP(S) URL to inspect, resolve, or compare.",
              "maxLength": 2048,
              "minLength": 1,
              "pattern": "^https?://",
              "type": "string"
            }
          },
          "required": [
            "url",
            "origin",
            "requested_method"
          ],
          "type": "object"
        },
        "bodyType": {
          "enum": [
            "json",
            "form-data",
            "text"
          ],
          "type": "string"
        },
        "method": {
          "enum": [
            "POST"
          ],
          "type": "string"
        },
        "type": {
          "const": "http",
          "type": "string"
        }
      },
      "required": [
        "type",
        "method",
        "bodyType",
        "body"
      ],
      "type": "object"
    },
    "output": {
      "properties": {
        "example": {
          "additionalProperties": false,
          "properties": {
            "capability": {
              "const": "cors.preflight",
              "description": "Public capability value used to scope this lookup."
            },
            "data": {
              "additionalProperties": false,
              "description": "Public data value used to scope this lookup.",
              "properties": {
                "allowed_headers": {
                  "description": "Public allowed headers value used to scope this lookup.",
                  "items": {
                    "type": "string"
                  },
                  "type": "array"
                },
                "allowed_methods": {
                  "description": "Public allowed methods value used to scope this lookup.",
                  "items": {
                    "type": "string"
                  },
                  "type": "array"
                },
                "allowed_origin": {
                  "description": "Public allowed origin value used to scope this lookup.",
                  "type": [
                    "string",
                    "null"
                  ]
                },
                "blockers": {
                  "description": "Public blockers value used to scope this lookup.",
                  "items": {
                    "type": "string"
                  },
                  "type": "array"
                },
                "credentials_allowed": {
                  "description": "Public credentials allowed value used to scope this lookup.",
                  "type": "boolean"
                },
                "final_url": {
                  "description": "Public final url value used to scope this lookup.",
                  "type": "string"
                },
                "headers_allowed": {
                  "description": "Public headers allowed value used to scope this lookup.",
                  "type": "boolean"
                },
                "method_allowed": {
                  "description": "Public method allowed value used to scope this lookup.",
                  "type": "boolean"
                },
                "origin_allowed": {
                  "description": "Public origin allowed value used to scope this lookup.",
                  "type": "boolean"
                },
                "preflight_passes": {
                  "description": "Public preflight passes value used to scope this lookup.",
                  "type": "boolean"
                },
                "provider_request_count": {
                  "const": 1,
                  "description": "Public provider request count value used to scope this lookup."
                },
                "redirect_count": {
                  "const": 0,
                  "description": "Public redirect count value used to scope this lookup."
                },
                "scope": {
                  "const": "observed_noncredentialed_cors_preflight_only",
                  "description": "Public scope value used to scope this lookup."
                },
                "status": {
                  "description": "Public status value used to scope this lookup.",
                  "maximum": 599,
                  "minimum": 100,
                  "type": "integer"
                },
                "warnings": {
                  "description": "Public warnings value used to scope this lookup.",
                  "items": {
                    "type": "string"
                  },
                  "type": "array"
                }
              },
              "required": [
                "status",
                "final_url",
                "redirect_count",
                "allowed_origin",
                "allowed_methods",
                "allowed_headers",
                "credentials_allowed",
                "origin_allowed",
                "method_allowed",
                "headers_allowed

This page as JSON