{
  "company": "Doormat Capital",
  "tool": "corscheck — CORS configuration checker",
  "for_whom": "Any developer debugging a CORS error, or an API owner who wants to confirm their allowlist actually behaves as intended.",
  "safety_note": "This tool never performs a live mutating request (POST/PUT/PATCH/DELETE) against a third-party endpoint. Non-GET/HEAD methods are checked via an OPTIONS preflight simulation only, exactly like a real browser would do before sending the real request.",
  "endpoints": {
    "GET /check": "FREE — GET /check?url=<url>&origin=<origin>&method=<method>&headers=<comma list>. Real CORS headers, preflight simulation, allowed/blocked verdict, misconfiguration warnings.",
    "GET /report": "paid, 0.02 USDC per call — GET /report?url=<url>&origins=<comma list>&method=<method>&headers=<comma list>. Multi-origin check + reflect-any-origin security probe + fix snippets."
  },
  "usage_examples": {
    "check": "GET /check?url=https://api.example.com/data&origin=https://your-app.com",
    "check_preflight": "GET /check?url=https://api.example.com/data&origin=https://your-app.com&method=PUT&headers=Authorization,X-Custom",
    "report": "GET /report?url=https://api.example.com/data&origins=https://your-app.com,http://localhost:3000"
  },
  "payment_method_for_report": "X-PAYMENT-TX header: send USDC on Base to 0x202B73254C28fA012BD11ff50425D94534b95594, then call /report with header 'X-PAYMENT-TX: <your tx hash>' -- or, from a browser with no way to set a header, add '&tx=<your tx hash>' to the URL instead. Verified read-only via Base's public RPC, no facilitator, no account.",
  "how_to_pay": [
    "1. Send 0.02 USDC on Base (network: base) to 0x202B73254C28fA012BD11ff50425D94534b95594",
    "2. Wait for that transaction to confirm (a few seconds on Base)",
    "3. Call GET /report?url=<https-url>&origins=<comma list> again, this time with header 'X-PAYMENT-TX: <your transaction hash>'"
  ],
  "pay_to": "0x202B73254C28fA012BD11ff50425D94534b95594",
  "network": "base",
  "asset": "0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913",
  "other_products": {
    "urls": [
      "https://jwtcheck.sebastiaan-ba3.workers.dev",
      "https://cronparse.sebastiaan-ba3.workers.dev",
      "https://mailcheck.sebastiaan-ba3.workers.dev",
      "https://metacheck.sebastiaan-ba3.workers.dev",
      "https://secheaders.sebastiaan-ba3.workers.dev",
      "https://crawlercheck.sebastiaan-ba3.workers.dev"
    ]
  },
  "contact": "t.me/doormatcapitalbot"
}