OrbSeekr Utility #001

COG Hosting Doctor

Paste the URL of a Cloud Optimized GeoTIFF. The doctor checks how your server actually delivers it — byte ranges, Content-Range, CORS, Content-Type, redirects and caching — not just whether the file is valid. Free, no login.

Terms in plain language

COG (Cloud Optimized GeoTIFF)
A GeoTIFF arranged so that a viewer can read just the part it needs over the internet instead of downloading the whole image.
HTTP Range Request
Asking the server for only a slice of a big file (e.g. bytes 0–16383). This is what makes COGs fast.
206 Partial Content
The server's answer meaning “here is only the slice you asked for”. 200 means it is sending the whole file.
Content-Range
A response label saying which slice was sent and how big the whole file is.
CORS
The setting that decides whether a web page on another website may read this file. Only matters for browser-based viewers.
Preflight
A permission check (OPTIONS request) a browser sends before requests with extra headers. A normal single byte-range read does not need one.
Expose-Headers
The list of response headers browser JavaScript is allowed to read. Content-Range must be on it.
Redirect
The server answering “the file is at another address”. Each one adds a round trip.
Cache-Control / ETag
Instructions for how long browsers and CDNs may reuse data, and a fingerprint to detect changes.
IFD / overview
The TIFF’s internal table of contents, and lower-resolution copies used when zoomed out.

Privacy & limits

  • The check runs on our server with a handful of small requests (about 20–100 KB in total, hard cap 2 MB). The full file is never downloaded.
  • URLs and results are not stored or logged. Query-string values (signed-URL tokens) are replaced with REDACTED in the report.
  • Only public https:// URLs on port 443. Private, local and cloud-metadata addresses are refused, including after redirects.
  • CORS is tested with Origin: https://example.com. If you allow only specific sites, a CORS warning is expected.
  • Results reflect what our server saw at that moment. CDNs can answer differently by region or cache state.
  • Layout checks (CHD010) focus on HTTP access; use rio-cogeo or GDAL's validator for full COG validation.

CLI: orbseekr cog-hosting-doctor <url> --json (exit 0 = pass, 1 = findings, 2 = error).