{"uid":"cap_LX_boYU9jWaMv19gSMwIM","slug":"response-header-access-control-allow-credentials-checker-ee690972","name":"Response Header: Access-Control-Allow-Credentials Checker","description":"The access-control-allow-credentials response header of a URL: whether it is present, its value, and a one-line reading of what the value means (or the risk of its absence for security headers). One header, one answer, for audits and monitoring scripts. $0.01 per check.","url":"https://site.intel.rallylive.ca/site/header/access-control-allow-credentials?utm_source=zero.xyz","method":"GET","headers":{},"bodySchema":{"type":"object","$schema":"https://json-schema.org/draft/2020-12/schema","required":["input"],"properties":{"input":{"type":"object","required":["type","method"],"properties":{"type":{"type":"string","const":"http"},"method":{"enum":["GET"],"type":"string"},"queryParams":{"type":"object","properties":{}}},"additionalProperties":false},"output":{"type":"object","required":["type"],"properties":{"type":{"type":"string"},"example":{"type":"object"}}}}},"responseSchema":null,"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.01","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.01/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.01","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.01","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_-xfNA4y448Se7gWG8llTJ","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.01","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Fetches a URL and returns whether the Access-Control-Allow-Credentials response header is present, its value, and a plain-language interpretation of what the value means for CORS security.","exampleAgentPrompt":"Check the Access-Control-Allow-Credentials response header on https://api.example.com and tell me whether it's present, what its value is, and whether there's any CORS security risk I should know about.","exampleUseCases":[{"title":"CORS security audit for API","prompt":"I'm doing a security review of our API at https://api.mycompany.com — can you check if the Access-Control-Allow-Credentials header is set, what its value is, and flag any risks?"},{"title":"Monitoring credentials header on production","prompt":"Set up a check on https://checkout.storefront.io — I want to know if the Access-Control-Allow-Credentials header changes or goes missing so I can catch CORS misconfigurations early."},{"title":"Third-party site CORS compliance check","prompt":"Before we integrate with https://payments.partner.io, can you verify what their Access-Control-Allow-Credentials header says and explain if that creates any cross-origin credential exposure risk?"}],"resultDescription":"Returns whether the Access-Control-Allow-Credentials header is present on the target URL's HTTP response, its exact value (e.g. 'true' or absent), and a one-line human-readable interpretation of the security implications — such as whether credentials like cookies are exposed to cross-origin requests or whether the absence of the header poses a risk.","failureModes":["Target URL is unreachable or times out — no header data returned","Target URL returns non-HTTP response (e.g. invalid domain) — error returned","Header is absent — response indicates absence with security risk note","Network or DNS resolution failure for target domain"],"whenToPreferThis":"Choose this endpoint when you need a fast, single-header answer specifically about CORS credential exposure (Access-Control-Allow-Credentials) on a given URL. Ideal for security audits, compliance checks, or monitoring pipelines where you only need this one header's status rather than a full HTTP header dump or CORS suite scan.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-10-02T00:46:20.331Z","isFirstParty":false,"canonicalSlug":"response-header-access-control-allow-credentials-checker-ee690972"}