Notes on CORS, proxies, and web security

Working notes from the team behind corsproxy.dev. Plain-English explanations and honest tradeoffs.

CORS in Next.js 16: Route Handlers and proxy.ts

Next.js doesn't send CORS headers for you, and its default OPTIONS response isn't enough on its own. Tested against Next.js 16.3, including the middleware.ts → proxy.ts rename that breaks older tutorials.

· Integration · ~7 min read

Cloudflare KV vs D1 vs Durable Objects, in production

corsproxy.dev uses all three Cloudflare storage primitives at once, for different pieces of the same request. Why each one earns its place, and the rule of thumb we use to pick between them.

· Architecture · ~6 min read

CORS proxy cookie forwarding: what we fixed

A CORS proxy that blindly relays your Cookie header to whatever target you give it can leak a session cookie to the wrong domain. The fix, and how to check your own proxy.

· Security · ~6 min read

corsproxy.dev vs cors.sh: an honest comparison

Two Cloudflare-edge CORS proxies, both with public source — so this one has receipts, not just marketing copy. Where cors.sh is ahead, where it isn't, straight from their own committed spec.

· Comparison · ~5 min read

When not to use a CORS proxy

A CORS proxy fixes one specific problem: a response missing Access-Control-Allow-Origin. Six situations where reaching for one is the wrong move, and what to do instead.

· Guide · ~6 min read

CORS preflight caching: how Access-Control-Max-Age works

Access-Control-Max-Age tells the browser how long to skip the OPTIONS preflight — but Chrome, Firefox, and Safari each cap it at a different ceiling, and a changed header resets the cache anyway.

· Performance · ~6 min read

An MCP server for safe API calls from AI agents

Give Claude Code, Cursor, or your own agent HTTP access that keeps API secrets out of the model, blocks internal addresses, and stops at a quota.

· Agents · ~5 min read

corsproxy.dev vs corsproxy.io: an honest comparison

Similar names, different strengths. Free tiers, pricing, uptime, secret handling, and open source side by side, including where corsproxy.io is ahead.

· Comparison · ~5 min read

CSP vs CORS: why your fetch is blocked

Content-Security-Policy and CORS block requests for different reasons and throw different console errors. How to tell them apart from the message text and fix each one.

· Security · ~6 min read

Do you need a CORS proxy in React Native or Expo?

Native fetch isn't subject to CORS at all — but Expo Web, RN Web, and WebView screens run in a real browser and are. How to tell which one you're hitting.

· Mobile · ~5 min read

CORS proxy for Webflow, Framer, and Bubble custom code

Custom code embeds run in the visitor's browser, so they hit CORS the same way any frontend does. Copy-paste fixes for all three, no backend required.

· No-code · ~5 min read

Your CORS proxy just got rate limited — now what?

Free public proxies share one pool of capacity across every user. Why that fails, what to check before picking the next one, and a one-line migration.

· Troubleshooting · ~5 min read

Call OpenAI, Notion, and Google Sheets from the browser without leaking your API key

CORS isn't what stops you, the secret key is. Keep it out of client-side JavaScript without writing a backend, and know what that still can't protect.

· Tutorial · ~6 min read

Rate limits and quotas on corsproxy.dev, explained

What counts against your daily quota, why you got a 429, when the counter resets, and how it's enforced atomically instead of eventually.

· Reference · ~4 min read

Blocking a country's traffic with Cloudflare WAF (without blocking everyone)

One country was 96% of our traffic and almost none of it real. The WAF rule that stopped it, the expression mistakes that block everyone or no one, and how to check it works.

· Ops · ~5 min read

Free CORS proxy: 7 options compared in 2026

cors-anywhere, allorigins, ThingProxy, corsproxy.io, and corsproxy.dev. Which ones are still maintained, what their limits are, and what to watch out for.

· Comparison · ~6 min read

CORS with cookies and credentials: the rules that bite

Your login sets a cookie but the next request comes back logged out. The four moving parts that all have to align, with code and the most common failures.

· Deep dive · ~8 min read

How to enable CORS in Node.js and Express

The one-line dev fix, the production-ready allowlist, the per-route configuration, and the common gotchas — with copy-paste code.

· Tutorial · ~6 min read

Migrating from cors-anywhere to corsproxy.dev

The public cors-anywhere.herokuapp.com demo is rate-limited to ~50 requests per hour. Here's the drop-in migration path with code for vanilla fetch, Axios, and helper wrappers.

· Migration · ~5 min read

Self-host vs managed CORS proxy: which one for which job?

Same proxy core, two operational shapes. Cost, control, security, and ops — when each one wins, and how to switch between them.

· Comparison · ~7 min read

5 ways to fix CORS in development

Vite proxy config, webpack-dev-server, server-side CORS, a flag-disabled browser, and a CORS proxy. Five practical fixes, ordered by how production-safe each one is.

· How-to · ~6 min read

How a CORS proxy works — and how it can be abused

CORS proxies are powerful and, by default, dangerous. Here's how an open relay can be weaponised, and what corsproxy.dev does to make sure ours isn't one.

· Security · ~9 min read

Why am I getting a CORS error? — a practical guide

The browser console says "blocked by CORS policy". What that actually means, why it happens, and three ways to fix it — with code.

· Tutorial · ~7 min read

Frequently asked questions

Logging policy, GDPR posture, authentication header forwarding, self-hosting options, and other things people email us about.

FAQ

One post a week, no marketing fluff.

Get new posts and glossary entries on CORS, web security, and proxy operations in your inbox. Unsubscribe in one click.