Security · Browser policy signals

CORS & Cookie Inspector

Inspect CORS response headers and cookie security metadata observed during a safe public GET request. This is passive inspection—not a custom-Origin or OPTIONS preflight simulator.

Public HTTP/HTTPS only. The shared Cloud Engine SSRF protections remain authoritative.