{"api":"v1","generated_at":"2026-09-15T21:51:10.623Z","licence":{"name":"CC BY 4.0","url":"https://creativecommons.org/licenses/by/4.0/","attribution":"TOLL, with a link to the page cited"},"page":"https://tollindex.com/e/cors-header-checker-underscoredone-com-check-de5f9a","pinned_page":"https://tollindex.com/e/cors-header-checker-underscoredone-com-check-de5f9a/at/2026-09-15T21-20Z","pinned":false,"method":"https://tollindex.com/ledger/method","snapshot_at":"2026-09-15T21:20:12.737Z","snapshot_stamp":"2026-09-15T21-20Z","endpoint":{"slug":"cors-header-checker-underscoredone-com-check-de5f9a","canonical_url":"https://cors-header-checker.underscoredone.com/check","resource":"https://cors-header-checker.underscoredone.com/check","http_method":"POST","type":"http","x402_version":2,"registries":["cdp"],"primary_registry":"cdp","curated_by_coinbase":false,"description":"Sends a real request to any URL you provide, attaches an Origin header, and reads back all six standard cross-origin permission headers the server returns. Tells you whether cross-origin requests are enabled at all, whether your specific origin is permitted, and shows every permission value exactly as the server sent it. Useful for finding why a browser is blocking a request, confirming a new deployment is configured correctly, or auditing whether a public API allows credentialed calls.","service_name":"CORS Header Checker","declared_category":null,"declared_tags":["cors headers","cors","cross origin","access-control-allow-origin","cors policy"],"route_template":null,"registry_updated":"2026-09-14T19:48:35.525Z"},"derived":{"note":"fields no registry supplies; TOLL derives them and marks them derived on the page","title":"check","category":"scraping","first_observed_by_toll":"2026-09-10T19:08:24.178Z","last_observed_by_toll":"2026-09-15T21:20:12.737Z","observation_began":"2026-09-10"},"presence":{"listed_now":true,"first_absent_at":null,"delisting_confirmed_at":null,"events":[{"registry":"cdp","at":"2026-09-10T19:08:24.178Z","event":"listed"}]},"accepts":[{"registry":"cdp","ordinal":0,"network":"eip155:8453","asset":"0x833589fcd6edb6e08f4c7c32d4f71b54bda02913","asset_name":"USD Coin","symbol":"USDC","decimals":6,"amount_display":"0.01 USDC","amount_units":0.01,"decimals_known":true,"pay_to":"0xE9740820225B3918b4ddd1292C7cA4Ca0e2C2F08","scheme":"exact"},{"registry":"cdp","ordinal":1,"network":"solana:5eykt4UsFv8P8NJdTREpY1vzqKqZKvdp","asset":"EPjFWdd5AufqSSqeM2qN1xzybapC8G4wEGGkZwyTDt1v","asset_name":null,"symbol":"USDC","decimals":6,"amount_display":"0.01 USDC","amount_units":0.01,"decimals_known":true,"pay_to":"8ugAWAXDB8V18kiUrGZTq1oMvU3C6Fxs8hfC6rvzQT3b","scheme":"exact"}],"counters":{"observed_at":"2026-09-15T21:20:12.737Z","calls_30d":3,"unique_payers_30d":3,"last_called_at":"2026-09-14T19:48:35.244Z"},"validation":{"latest":{"observed_at":"2026-09-15T06:46:08.046Z","state":"pass","failed_checks":[],"endpoint_http_status":402,"run_id":"daily-2026-09-15"},"uptime":[{"days":7,"observed":5,"passed":5,"ratio":1},{"days":30,"observed":5,"passed":5,"ratio":1},{"days":90,"observed":5,"passed":5,"ratio":1}],"history_90d":[{"observed_at":"2026-09-15T06:46:08.046Z","state":"pass","failed_checks":[],"run_id":"daily-2026-09-15","state_changed":false},{"observed_at":"2026-09-14T06:14:08.153Z","state":"pass","failed_checks":[],"run_id":"daily-2026-09-14","state_changed":false},{"observed_at":"2026-09-13T06:05:12.154Z","state":"pass","failed_checks":[],"run_id":"daily-2026-09-13","state_changed":false},{"observed_at":"2026-09-12T08:22:29.223Z","state":"pass","failed_checks":[],"run_id":"daily-2026-09-12","state_changed":false},{"observed_at":"2026-09-11T13:48:26.491Z","state":"pass","failed_checks":[],"run_id":"daily-2026-09-11","state_changed":true}]},"seller":{"wallet":"0xE9740820225B3918b4ddd1292C7cA4Ca0e2C2F08","page":"https://tollindex.com/seller/0xE9740820225B3918b4ddd1292C7cA4Ca0e2C2F08","endpoints":28,"hosts":28},"reports":0,"registry_record":{"cdp":[{"tags":["cors headers","cors","cross origin","access-control-allow-origin","cors policy"],"type":"http","accepts":[{"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","extra":{"name":"USD Coin","version":"2"},"payTo":"0xE9740820225B3918b4ddd1292C7cA4Ca0e2C2F08","amount":"10000","scheme":"exact","network":"eip155:8453","maxTimeoutSeconds":300},{"asset":"EPjFWdd5AufqSSqeM2qN1xzybapC8G4wEGGkZwyTDt1v","extra":{"feePayer":"Hc3sdEAsCGQcpgfivywog9uwtk8gUBUZgsxdME1EJy88"},"payTo":"8ugAWAXDB8V18kiUrGZTq1oMvU3C6Fxs8hfC6rvzQT3b","amount":"10000","scheme":"exact","network":"solana:5eykt4UsFv8P8NJdTREpY1vzqKqZKvdp","maxTimeoutSeconds":300}],"quality":{"lastCalledAt":"2026-09-14T19:48:35.244Z","l30DaysTotalCalls":3,"l30DaysUniquePayers":3},"resource":"https://cors-header-checker.underscoredone.com/check","extensions":{"bazaar":{"info":{"input":{"body":{"url":"https://api.github.com","origin":"https://myapp.com"},"type":"http","method":"POST","bodyType":"json"},"output":{"type":"json","example":{"url":"https://api.github.com","error":"","status":200,"headers":{"access-control-max-age":null,"access-control-allow-origin":"https://github.com","access-control-allow-headers":null,"access-control-allow-methods":null,"access-control-expose-headers":"ETag, Link, Location, Retry-After, X-GitHub-OTP, X-RateLimit-Limit, X-RateLimit-Remaining, X-RateLimit-Used, X-RateLimit-Resource, X-RateLimit-Reset, X-OAuth-Scopes, X-Accepted-OAuth-Scopes, X-Poll-Interval, X-GitHub-Media-Type, X-GitHub-SSO, X-GitHub-Request-Id, Deprecation, Sunset","access-control-allow-credentials":null},"api_version":"1.0.0","cors_enabled":true,"origin_tested":"https://myapp.com","origin_allowed":false}}},"schema":{"type":"object","$schema":"https://json-schema.org/draft/2020-12/schema","required":["input"],"properties":{"input":{"type":"object","required":["type","method","bodyType","body"],"properties":{"body":{"type":"object","required":["url"],"properties":{"url":{"type":"string","description":"The full web address of the endpoint you want to check — must start with http:// or https://."},"origin":{"type":"string","description":"The website address you want to test cross-origin access from, for example https://myapp.com. Defaults to https://example.com if you leave it out."}},"additionalProperties":false},"type":{"type":"string","const":"http"},"method":{"enum":["POST","PUT","PATCH"],"type":"string"},"bodyType":{"enum":["json","form-data","text"],"type":"string"}},"additionalProperties":false},"output":{"type":"object","required":["type"],"properties":{"type":{"type":"string"},"example":{"type":"object","required":["api_version","url","origin_tested","status","cors_enabled","origin_allowed","headers","error"],"properties":{"url":{"type":"string"},"error":{"type":"string"},"status":{"type":"integer"},"headers":{"type":"object","additionalProperties":true},"api_version":{"type":"string"},"cors_enabled":{"type":"boolean"},"origin_tested":{"type":"string"},"origin_allowed":{"type":"boolean"}}}}}}}}},"description":"Sends a real request to any URL you provide, attaches an Origin header, and reads back all six standard cross-origin permission headers the server returns. Tells you whether cross-origin requests are enabled at all, whether your specific origin is permitted, and shows every permission value exactly as the server sent it. Useful for finding why a browser is blocking a request, confirming a new deployment is configured correctly, or auditing whether a public API allows credentialed calls.","lastUpdated":"2026-09-14T19:48:35.525Z","serviceName":"CORS Header Checker","x402Version":2}]}}