Overview
Developer tool to bypass CORS restrictions during local testing. Features profiles, allowlist, and auto-off timer for safety.
CORS Helper - Developer Tool for Local Testing โ ๏ธ FOR DEVELOPERS ONLY - This tool bypasses browser security. Use only during development! ๐ฏ WHAT IT DOES Bypass CORS (Cross-Origin Resource Sharing) restrictions when testing local applications. Perfect for frontend developers working with APIs on different ports or domains. โจ KEY FEATURES Smart Profile System • Create multiple profiles for different projects • Domain allowlist per profile • Quick switch between configurations • Import/export profiles as JSON Privacy-First Design • Debug logging OFF by default • No tracking or analytics • No external servers • All data stored locally • You control what gets logged Auto-Off Timer • 10 minutes, 30 minutes, 2 hours, or infinite • Countdown badge shows remaining time • Global mode defaults to 10-min timer for safety • Never leave CORS accidentally disabled Domain Management • Allowlist mode: Only specified domains (recommended) • Global mode: All domains (use with caution) • Right-click context menu: "Allow this domain" • "Allow Active Tab" button for instant access • Preset buttons for common localhost ports Debug Logging (Optional) • Track which requests are modified • View HTTP status codes and methods • Preflight failure detection with helpful hints • Logs capped at 60 entries, stored locally only Built-In Test Console • Test API endpoints directly from options page • Supports GET, POST, PUT, PATCH, DELETE • Add custom headers to trigger preflight • View all CORS headers in response • JSON formatting and error troubleshooting ๐จ USER EXPERIENCE • Dynamic icons for different modes (off/allowlist/global) • Keyboard shortcuts for quick actions • Dark mode support • Clean, modern interface • Onboarding wizard for first-time users • Real-time countdown badge ๐ SECURITY & PRIVACY โ Manifest V3 compliant โ No external API calls โ No tracking or analytics โ Open source code โ Data never leaves your browser โ Debug logging OFF by default โ Clear privacy policy ๐ COMMON USE CASES 1. Test React/Vue/Angular apps with backend APIs on different ports 2. Connect microservices running locally on different ports 3. Test third-party APIs without CORS restrictions 4. Develop Chrome extensions with cross-origin requests 5. Connect local dev server to mobile test devices โ๏ธ HOW IT WORKS Uses Chrome's declarativeNetRequest API to modify response headers: • Access-Control-Allow-Origin: * • Access-Control-Allow-Methods: GET, POST, PUT, PATCH, DELETE, OPTIONS • Access-Control-Allow-Headers: * • Access-Control-Expose-Headers: * • Access-Control-Allow-Credentials: true ๐ก๏ธ SAFETY FEATURES • Auto-off timer prevents leaving CORS disabled • Visual indicators show current state • Confirmation dialogs prevent accidents • Allowlist mode more secure than global • Per-profile isolation ๐ก BEST PRACTICES • Use Allowlist mode for better security • Enable Auto-off timer when using Global mode • Turn on Debug logging only when troubleshooting • Create separate profiles for different projects • Disable when not actively testing โ ๏ธ IMPORTANT DISCLAIMER FOR DEVELOPMENT USE ONLY. Disabling CORS removes an important browser security feature. Only use during local development on domains you control. Always disable when browsing normally. ๐ WHY CORS HELPER? โ Privacy-focused (no tracking) โ Modern Manifest V3 โ Advanced features (profiles, timer, logging) โ Active development โ Clean, intuitive UI โ Comprehensive documentation Happy coding! ๐
Details
- Version3.3.2
- UpdatedOctober 19, 2025
- Offered byNRKGo
- Size254KiB
- LanguagesEnglish (United States)
- Developer
Email
team.nrkgo@gmail.com - Non-traderThis developer has not identified itself as a trader. For consumers in the European Union, please note that consumer rights do not apply to contracts between you and this developer.
Privacy
This developer declares that your data is
- Not being sold to third parties, outside of the approved use cases
- Not being used or transferred for purposes that are unrelated to the item's core functionality
- Not being used or transferred to determine creditworthiness or for lending purposes

