go-supertools
Network Tools

HTTP Methods Auditor

See which HTTP methods a server allows: probes GET, HEAD, OPTIONS and TRACE and reads the Allow header for the rest.

Looks up live data What you enter is sent to our server to fetch live results from public sources. Results are cached briefly.

About this tool

Enter a web address to see how the server responds to the safe, read-only HTTP methods GET, HEAD, OPTIONS and TRACE, and to read the Allow header from an OPTIONS response. Methods that change data (POST, PUT, PATCH, DELETE) are deliberately never sent to your site; they are reported only from the Allow header when the server publishes one. A method counts as allowed when the status is below 400, and redirects are not followed. Unexpectedly enabled methods such as TRACE, or write methods listed on a public endpoint, are worth reviewing. The request goes through our server.

How to use it

  1. Enter the URL of the page or endpoint to test.
  2. Press the audit button.
  3. Read the response status for GET, HEAD, OPTIONS and TRACE.
  4. Compare the Allow header (if present) with what the endpoint should support.

Common problems

The write methods show "not sent"
That is intentional: sending POST, PUT, PATCH or DELETE could change data on a live site. The Allow header, when present, shows what the server says it accepts.
No Allow header
Many servers don't publish one. The result then only shows how GET, HEAD, OPTIONS and TRACE behave.
A 4xx or 5xx status counts as not allowed
Authentication or routing (401, 403, 404, 405) can block a method that is otherwise supported. Test the exact endpoint you care about.
A redirect counts as allowed
Redirects are not followed, so a 301 or 302 status is below 400 and shows as allowed. Test the final URL.