Comparison

Free CORS proxy — 7 options compared in 2026

A practical look at the free CORS proxy services that are still actually running in 2026: where they cap you, what they cost above the cap, and whether you should trust them with the URLs you send through.

· ~7 min read · Updated Sep 30, 2026

What "free CORS proxy" actually means

A CORS proxy forwards your browser's request to a third-party API and rewrites the response with the right Access-Control-Allow-Origin header. "Free" usually means one of three things:

The seven options

1. cors-anywhere.herokuapp.com

The original. Open-source Node project by Rob--W. The demo instance now requires you to click a button on a different page before it'll proxy for you, and even then it's limited to ~50 requests/hour. Production use stopped being viable in 2021.

Best for: nostalgia. Worst for: anything you want to keep working.

Migration: see the dedicated guide.

2. api.allorigins.win

A volunteer-run open proxy that wraps the response in JSONP or returns it as JSON. No API key, no rate limits documented, but heavy use will get you blocked. The maintainer accepts donations.

Best for: quick demos and tutorials. Worst for: anything where the response shape matters — wrapping responses adds an extra layer your client has to parse.

3. ThingProxy by Freeboard

thingproxy.freeboard.io/fetch/<url>. Originally bundled with the Freeboard dashboard product. Still up but rate-limited to ~10 requests/sec per IP. Returns the upstream response verbatim, including the original status code. Reliable for occasional use, not for production.

4. corsproxy.io

A commercial managed proxy. Requests carry an API key: corsproxy.io/?key=YOUR_KEY&url=https%3A%2F%2Fapi.example.com%2Fdata. The free tier is 10,000 requests and 1 GB a month, browser-side only, with no uptime commitment; their pricing page says production features aren't included. Paid plans are $5/month (Hobby) and $29/month (Production), with uptime SLAs, plus extras like caching and format conversion. Has a usage dashboard. Full comparison with corsproxy.dev.

Best for: teams who want a quick managed solution without thinking about it.

5. cors.sh

A commercial managed proxy built on Cloudflare's edge, from Grida, Inc. — and, unusually for this list, MIT-licensed and public, so this one we could actually check instead of just reading the marketing copy. Free tier is 10,000 requests and 5 GB a month with origin-pinned "live keys" (the key is public by design; the browser's unforgeable Origin header is the real auth). Pro is $4/month for 500,000 requests, 500 GB, no hourly throttling, up to 6 MB per request. Their own internal spec, committed to the repo as the documented source of truth for the service's behavior, lists exactly what every request is checked against — origin pinning, target allowlists, size caps, rate limits — and private-network/SSRF filtering is not one of them. Full comparison: corsproxy.dev vs cors.sh.

Best for: the most generous free/Pro quota of any managed option here. Worst for: anyone who needs the proxy to refuse a private/internal target — per their own spec, nothing currently stops it from fetching one.

6. cors.lol

A free, open-source (Node) proxy: prefix https://api.cors.lol/?url=. Marketed as "unlimited requests" on the free tier, though rate-limited with the specifics undocumented; a $35 lifetime plan removes the rate limit and raises the per-request cap to 100 MB. No API key, no origin locking, no security documentation of any kind on the marketing site. Blog and copyright footer are dated 2024, which doesn't necessarily mean it's abandoned but is worth checking before depending on it.

Best for: a quick no-signup prototype. Worst for: anything where you'd want to know who else can call the same open endpoint, or whether it'll fetch a target you didn't intend.

7. corsproxy.dev (us)

Disclosure: this is our service, on this site. Managed API with origin-locked API keys, exact daily limits (Cloudflare Durable Objects, no burst overage), SSRF protection — private/internal targets blocked on the resolved IP of every connection, including redirects, which a hostname-only check can't catch — plus a daily bandwidth cap, abuse auto-flagging, and a dashboard with your last 100 calls. It can keep third-party API secrets out of the browser with managed upstream headers, cache responses at the edge with ttl (Pro), and rewrite headers per request. Free tier is 500 requests/day, no credit card; Pro is $5/month for 20,000/day. Plus the underlying Go proxy is MIT-licensed and self-hostable — so when you outgrow the managed tier, you can move to your own infra without rewriting client code. Of the seven proxies here, we're the only one that documents what happens when a client asks it to fetch a private address.

The comparison table

Service Free limit Paid, from API key SSRF protection Self-host? Status
cors-anywhere~50/hr (demo)—NoNoYesDemo only
alloriginsUnmetered (best effort)—NoNot documentedNoActive
ThingProxy~10 req/sec—NoNot documentedNoActive
corsproxy.io10k/month (not for production)$5/mo (250k)YesNot documentedNoActive
cors.sh10k/month, 5GB$4/mo (500k)YesNo (per their own spec)Yes (MIT, full monorepo)Active
cors.lol"Unlimited" (rate-limited)$35 lifetimeNoNot documentedYesActive (site dated 2024)
corsproxy.dev500/day$5/mo (20k/day)YesYes, documentedYes (MIT)Active

"Not documented" means the service's own pricing/docs/marketing pages make no mention of blocking private-network or internal targets — not that we tested and found it missing. cors.sh is the exception: its source is public, so "No" there is read from its own committed spec of documented behavior, not an absence of marketing copy. For everyone else, if it matters to you, ask the vendor directly before you rely on it.

What to actually watch for

"Free" is a feature, but so are the things that make a proxy not embarrassing to depend on:

For the full security argument, see how a CORS proxy can be abused.

What we'd actually recommend

  1. You control the upstream. Don't use any proxy. Configure CORS on the upstream. It's correct and free.
  2. You're in dev and just need it to work. Use your build tool's proxy config. 5 ways covered here.
  3. You need a managed proxy in production. Pick one that has API keys, per-account rate limits, and a documented security stance. corsproxy.dev is our answer: it's the only one of the seven here that documents what it does with a private-network target, and $5/month for 20,000 requests/day gives you more total quota than any other managed option here, even though cors.sh's $4/month tier is very slightly cheaper per request.
  4. You can't send your data through anyone else. Self-host. Our Go binary is MIT; cors-anywhere is the other obvious open-source choice but is heavier (Node + lots of features).

Get 500 free requests/day

No credit card. Email-only sign-in. Self-host the same code later if you outgrow it.

Create a free account →