Cross-Origin API Request Builder

Build and send real GET/POST/PUT/DELETE requests from your browser to debug APIs and CORS.

The Cross-Origin API Request Builder lets you build and send real HTTP requests, GET, POST, PUT, or DELETE, from your browser to test an API or to reproduce a problem. You set the method, the URL, the headers, and the body, and the tool shows the response you get back. That makes it ideal for checking whether an endpoint behaves as documented, for confirming that a payload is accepted, and for diagnosing cross origin issues directly. Remember that the browser still enforces same origin rules, so a cross origin call only succeeds if the target API allows your origin, and your requests come from your own device, not from ours. Testing an API from the browser is useful precisely because the browser applies the same rules a real client does, which means the constraints you hit are the ones your application will hit too. Setting the method, the URL, the headers, and the body and then reading the response back confirms whether an endpoint behaves as documented, whether a payload is accepted at all, and whether authentication headers are being read the way you expect. It is also the fastest way to distinguish an API problem from a client problem: if the same request succeeds here and fails in your application, the difference is in how the application builds the request rather than in the server. The important limitation to understand is the same origin policy. The browser will block a cross origin request unless the target explicitly permits your origin through its response headers, so an error about cross origin access is not evidence of a broken API but of a header that was not sent, and the server has to be changed to fix it. Requests are issued from your own device, so credentials you enter are never routed through us.

Private by design. Every tool runs 100% in your browser — your code, text, and tokens never leave your device. Nothing is uploaded or stored.
Request Builder
This runs entirely in your browser. Cross-origin calls only succeed when the target server returns Access-Control-Allow-Origin. For endpoints you do not control, run the request from your own backend or a proxy — a static site cannot bypass CORS for you.

Response headers and body appear here.

Frequently Asked Questions

Is it safe to send requests from my browser?

Yes — requests originate from your own browser and are not stored. Note that CORS may still block cross-origin calls unless the target API allows your origin.

Which method should I use to test a write?

Use POST/PUT/DELETE against a staging endpoint, never production, unless you intend the side effect. The builder shows the exact payload and headers before you send.

Why is my Authorization header stripped?

Some browsers hide Authorization in certain CORS scenarios; the server must allow it via Access-Control-Allow-Headers. The CORS Header Generator can produce the right config.

Related tools from our network

A focused set of free calculators and guides across related topics — no account required.