Next.js doesn't send CORS headers for you, and its default OPTIONS response isn't enough on its own. Tested against Next.js 16.3, including the middleware.ts → proxy.ts rename that breaks older tutorials.
corsproxy.dev uses all three Cloudflare storage primitives at once, for different pieces of the same request. Why each one earns its place, and the rule of thumb we use to pick between them.
A CORS proxy that blindly relays your Cookie header to whatever target you give it can leak a session cookie to the wrong domain. The fix, and how to check your own proxy.
Two Cloudflare-edge CORS proxies, both with public source — so this one has receipts, not just marketing copy. Where cors.sh is ahead, where it isn't, straight from their own committed spec.
A CORS proxy fixes one specific problem: a response missing Access-Control-Allow-Origin. Six situations where reaching for one is the wrong move, and what to do instead.
Access-Control-Max-Age tells the browser how long to skip the OPTIONS preflight — but Chrome, Firefox, and Safari each cap it at a different ceiling, and a changed header resets the cache anyway.
Content-Security-Policy and CORS block requests for different reasons and throw different console errors. How to tell them apart from the message text and fix each one.
Native fetch isn't subject to CORS at all — but Expo Web, RN Web, and WebView screens run in a real browser and are. How to tell which one you're hitting.
One country was 96% of our traffic and almost none of it real. The WAF rule that stopped it, the expression mistakes that block everyone or no one, and how to check it works.
cors-anywhere, allorigins, ThingProxy, corsproxy.io, and corsproxy.dev. Which ones are still maintained, what their limits are, and what to watch out for.
Your login sets a cookie but the next request comes back logged out. The four moving parts that all have to align, with code and the most common failures.
The public cors-anywhere.herokuapp.com demo is rate-limited to ~50 requests per hour. Here's the drop-in migration path with code for vanilla fetch, Axios, and helper wrappers.
Vite proxy config, webpack-dev-server, server-side CORS, a flag-disabled browser, and a CORS proxy. Five practical fixes, ordered by how production-safe each one is.
CORS proxies are powerful and, by default, dangerous. Here's how an open relay can be weaponised, and what corsproxy.dev does to make sure ours isn't one.