Skip to main content
Prerequisite: A Vercel protection bypass secret.
Send the bypass secret in headers or in query parameters. CORS blocks the headers on some apps; the query parameters still work there.

Option A: headers

In the test’s Network options, add:
These headers are sent with every request in the session, including third-party script requests. If you see CORS errors, use query parameters instead.

Option B: query parameters

Override the base URL in the test’s General options:
Vercel sets the bypass as a cookie for the rest of the session, so subsequent requests don’t need the query string.