Skip to content
New Try a request in the playground

Call any API from the browser. Without the CORS errors.

Proxify is a CORS proxy and API gateway. Send a request through it with a key locked to your site, and get back the response your browser was blocking.

  • Keys locked to your origins
  • No card required to sign up

Drop-in

One URL prefix. No SDK, no server of your own.

Keep your existing fetch call and send it through Proxify. The upstream status and headers come back as the API sent them, with the CORS headers your browser needs added.

Proxy reference
fetch.js
const target = 'https://api.github.com/repos/withastro/astro';

const response = await fetch(
  `https://api.proxifyedge.com/proxy?url=${encodeURIComponent(target)}`,
  { headers: { 'X-API-Key': 'pk_your_public_key' } },
);

const repo = await response.json();
terminal
curl "https://api.proxifyedge.com/proxy?url=https://api.github.com/repos/withastro/astro" \
  -H "X-API-Key: pk_your_public_key"

Working in three steps

From a blocked request to a working one, without touching the API you are calling.

  1. 1

    Create an account

    Sign up and you get a public API key straight away. No card is needed to sign up.

  2. 2

    Lock the key to your site

    List the origins allowed to use the key. Requests from anywhere else are refused, so the key is safe to ship in a browser bundle.

  3. 3

    Prefix the URL

    Send the request to api.proxifyedge.com/proxy?url=… with your key. Proxify adds the CORS headers the browser was missing.

More than a proxy

The parts of an API gateway a browser app actually needs, configured from the dashboard.

  • Origin-locked keys

    Live keys answer only the origins you list, so they are safe in a browser bundle. Test keys answer any origin while you develop.

  • Secrets vault

    Store upstream API tokens server-side and reference them as {{secret.NAME}}. They never reach the browser.

  • Signed URLs

    Require an HMAC signature and expiry on every request, so a copied link stops working when it should.

  • Quotas and rate limits

    Per-key monthly quotas and requests-per-second limits, reported back on every response in X-Proxify-RateLimit headers.

  • Edge modules

    Upload a WebAssembly module to rewrite requests and responses inline, without running a server of your own.

  • Record and replay

    Capture upstream responses into cassettes and replay them for demos, tests and offline development.

  • Batch requests

    Send several upstream requests in one round trip and get every response back together.

  • WebSocket tunnel

    Proxy WebSocket connections as well as HTTP, with the same keys and the same origin rules.

  • Hardened by default

    An SSRF guard refuses private and internal addresses, and a web application firewall inspects every request.

Ship the feature you were blocked on.

Create an account, lock your key to your site, and make your first request in minutes.

Are you sure?