โšก White.market ยท CORS Exploit v3

GraphQL Credential Theft Toolkit ยท Inline Response Viewer
Auth status: not checked
Successful
0
Failed
0
Data (KB)
0.00
Total Queries
0
๐Ÿ”ง Global Request Headers applied to every request ยท browser may override some
These headers are merged into all fetch calls. Content-Type and credentials are always set internally. Headers the browser controls (e.g. Cookie, User-Agent, Origin) cannot be set from JS โ€” they are sent automatically via credentials: include. Use this to inject custom tokens, Authorization: Bearer โ€ฆ, x-api-key, etc.
๐Ÿ”ง Global Request Headers merged into every request
These headers are sent with all requests. Content-Type: application/json is always set automatically. Browser-controlled headers (Cookie, User-Agent, Origin, Referer, Sec-Fetch-*) are sent automatically via credentials: include โ€” you cannot set them here. Use this for: Authorization: Bearer <accessToken>, x-api-key, custom session headers, etc.
Preset Queries
Custom Query
โ–ถ Per-Request Header Overrides overrides globals for this request only
Results 0 entries
โฌก
No queries executed yet.
Run auth check or select queries to begin.