Item logo image for allow cors - access-control-allow-origin

allow cors - access-control-allow-origin

Item media 1 (screenshot) for allow cors - access-control-allow-origin

Overview

bypass cors (access-control-allow-origin) errors, strip csp and x-frame-options security headers, and redirect api requests.

allow cors - access-control-allow-origin is a flat, lightweight developer utility to bypass cors, strip security headers, and configure custom redirects during local api testing. it runs 100% locally in your browser using native manifest v3 declarative rules, requiring zero idle cpu overhead and providing full compatibility with modern security standards. key features: * cors bypass: dynamically modifies response headers to permit cross-origin api queries. * credentials unblock: resolves browser wildcard blocks by matching the active tab's origin and injecting access-control-allow-credentials: true. * auto-disable alarm: automatically switches off the extension after 1, 10, 30, or 60 minutes using native background chrome alarms to prevent security leaks. * redirect mapping: redirects remote api patterns or javascript files (e.g. *zoologyfibre*/*.js*) to local mock routes (e.g. http://localhost:3000/mock.js). * headers stripping: removes content-security-policy (csp, x-webkit-csp, x-content-security-policy) and x-frame-options (frame-options) headers to test frames and embedded resources. * rules mode: choose between blocklist (allow all except exclusions) and allowlist (allow only custom domains) modes. * request counter: tracks intercepted and modified calls in real-time. all overrides run locally. no data is tracked or collected.

Details

  • Version
    1.0
  • Updated
    July 8, 2026
  • Offered by
    ananaydubey
  • Size
    15.71KiB
  • Languages
    English
  • Developer
    Ananay Dubey
    Shivalik Hostel Punjab Engineering College, Sector 12 Chandigarh, Chandigarh 160012 IN
    Email
    dubeyananay@gmail.com
  • Non-trader
    This developer has not identified itself as a trader. For consumers in the European Union, please note that consumer rights do not apply to contracts between you and this developer.

Privacy

Manage extensions and learn how they're being used in your organization
The developer has disclosed that it will not collect or use your data. To learn more, see the developer’s privacy policy.

This developer declares that your data is

  • Not being sold to third parties, outside of the approved use cases
  • Not being used or transferred for purposes that are unrelated to the item's core functionality
  • Not being used or transferred to determine creditworthiness or for lending purposes

Support

For help with questions, suggestions, or problems, visit the developer's support site

Related

CORS Unblock

4.2

Temporarily unblock CORS for development and testing purposes

DevHeader: Custom Headers & Redirect Rules

5.0

Modify request & response HTTP headers and redirect URLs per domain. Multiple named profiles for dev, staging, and prod.

Ignore X-Frame headers

4.4

Drops X-Frame-Options and Content-Security-Policy HTTP response headers, allowing all pages to be iframed.

Header Editor - Modify Request & Response Headers

0.0

Modify request headers, response headers and redirect URLs, with rules isolated per site.

HTTP Interceptor

5.0

Intercept and modify HTTP requests & responses: URL redirects, headers, query params, and response body replacement.

Anti-CORS, anti-CSP

4.1

Enable cross origin requests blocked by CORS or CSP. Disable CORS and CSP in selected hostnames, preserve security of other websites

Allow CORS

4.8

Enable this extension to bypass CORS errors and make API calls from different domains seamlessly

Lazy Header Editor - Modify HTTP Headers

0.0

Add, modify, and remove HTTP request and response headers, redirect URLs, and manage multiple header profiles.

XApi HTTP Client - API Tool, Modify Header & Response

0.0

Intercept, debug, modify header & response, replay HTTP requests. Comprehensive API client & cURL support in Chrome DevTools.

Netify

4.6

Debugging proxy that will allow you to intercept and mutate requests from a web page

CORS Unblock

4.9

Easily bypass CORS errors during development with a simple ON/OFF toggle.

SA CORS Unblock

2.3

An extension to help to bypass CORS security errors on superannotate domains

CORS Unblock

4.2

Temporarily unblock CORS for development and testing purposes

DevHeader: Custom Headers & Redirect Rules

5.0

Modify request & response HTTP headers and redirect URLs per domain. Multiple named profiles for dev, staging, and prod.

Ignore X-Frame headers

4.4

Drops X-Frame-Options and Content-Security-Policy HTTP response headers, allowing all pages to be iframed.

Header Editor - Modify Request & Response Headers

0.0

Modify request headers, response headers and redirect URLs, with rules isolated per site.

HTTP Interceptor

5.0

Intercept and modify HTTP requests & responses: URL redirects, headers, query params, and response body replacement.

Anti-CORS, anti-CSP

4.1

Enable cross origin requests blocked by CORS or CSP. Disable CORS and CSP in selected hostnames, preserve security of other websites

Allow CORS

4.8

Enable this extension to bypass CORS errors and make API calls from different domains seamlessly

Lazy Header Editor - Modify HTTP Headers

0.0

Add, modify, and remove HTTP request and response headers, redirect URLs, and manage multiple header profiles.

Google apps