Free CORS proxy — 7 options compared in 2026
A practical look at the free CORS proxy services that are still actually running in 2026: where they cap you, what they cost above the cap, and whether you should trust them with the URLs you send through.
What "free CORS proxy" actually means
A CORS proxy forwards your browser's request to a third-party API and rewrites the response with the right Access-Control-Allow-Origin header. "Free" usually means one of three things:
- A demo instance with strict per-IP rate limits (cors-anywhere).
- An open service funded by ads, donations, or a parent product (allorigins, ThingProxy, cors.lol).
- A freemium SaaS with a free tier and paid tiers above it (corsproxy.io, cors.sh, corsproxy.dev).
The seven options
1. cors-anywhere.herokuapp.com
The original. Open-source Node project by Rob--W. The demo instance now requires you to click a button on a different page before it'll proxy for you, and even then it's limited to ~50 requests/hour. Production use stopped being viable in 2021.
Best for: nostalgia. Worst for: anything you want to keep working.
Migration: see the dedicated guide.
2. api.allorigins.win
A volunteer-run open proxy that wraps the response in JSONP or returns it as JSON. No API key, no rate limits documented, but heavy use will get you blocked. The maintainer accepts donations.
Best for: quick demos and tutorials. Worst for: anything where the response shape matters — wrapping responses adds an extra layer your client has to parse.
3. ThingProxy by Freeboard
thingproxy.freeboard.io/fetch/<url>. Originally bundled with the Freeboard dashboard product. Still up but rate-limited to ~10 requests/sec per IP. Returns the upstream response verbatim, including the original status code. Reliable for occasional use, not for production.
4. corsproxy.io
A commercial managed proxy. Requests carry an API key: corsproxy.io/?key=YOUR_KEY&url=https%3A%2F%2Fapi.example.com%2Fdata. The free tier is 10,000 requests and 1 GB a month, browser-side only, with no uptime commitment; their pricing page says production features aren't included. Paid plans are $5/month (Hobby) and $29/month (Production), with uptime SLAs, plus extras like caching and format conversion. Has a usage dashboard. Full comparison with corsproxy.dev.
Best for: teams who want a quick managed solution without thinking about it.
5. cors.sh
A commercial managed proxy built on Cloudflare's edge, from Grida, Inc. — and, unusually for this list, MIT-licensed and public, so this one we could actually check instead of just reading the marketing copy. Free tier is 10,000 requests and 5 GB a month with origin-pinned "live keys" (the key is public by design; the browser's unforgeable Origin header is the real auth). Pro is $4/month for 500,000 requests, 500 GB, no hourly throttling, up to 6 MB per request. Their own internal spec, committed to the repo as the documented source of truth for the service's behavior, lists exactly what every request is checked against — origin pinning, target allowlists, size caps, rate limits — and private-network/SSRF filtering is not one of them. Full comparison: corsproxy.dev vs cors.sh.
Best for: the most generous free/Pro quota of any managed option here. Worst for: anyone who needs the proxy to refuse a private/internal target — per their own spec, nothing currently stops it from fetching one.
6. cors.lol
A free, open-source (Node) proxy: prefix https://api.cors.lol/?url=. Marketed as "unlimited requests" on the free tier, though rate-limited with the specifics undocumented; a $35 lifetime plan removes the rate limit and raises the per-request cap to 100 MB. No API key, no origin locking, no security documentation of any kind on the marketing site. Blog and copyright footer are dated 2024, which doesn't necessarily mean it's abandoned but is worth checking before depending on it.
Best for: a quick no-signup prototype. Worst for: anything where you'd want to know who else can call the same open endpoint, or whether it'll fetch a target you didn't intend.
7. corsproxy.dev (us)
Disclosure: this is our service, on this site. Managed API with origin-locked API keys, exact daily limits (Cloudflare Durable Objects, no burst overage), SSRF protection — private/internal targets blocked on the resolved IP of every connection, including redirects, which a hostname-only check can't catch — plus a daily bandwidth cap, abuse auto-flagging, and a dashboard with your last 100 calls. It can keep third-party API secrets out of the browser with managed upstream headers, cache responses at the edge with ttl (Pro), and rewrite headers per request. Free tier is 500 requests/day, no credit card; Pro is $5/month for 20,000/day. Plus the underlying Go proxy is MIT-licensed and self-hostable — so when you outgrow the managed tier, you can move to your own infra without rewriting client code. Of the seven proxies here, we're the only one that documents what happens when a client asks it to fetch a private address.
The comparison table
| Service | Free limit | Paid, from | API key | SSRF protection | Self-host? | Status |
|---|---|---|---|---|---|---|
| cors-anywhere | ~50/hr (demo) | — | No | No | Yes | Demo only |
| allorigins | Unmetered (best effort) | — | No | Not documented | No | Active |
| ThingProxy | ~10 req/sec | — | No | Not documented | No | Active |
| corsproxy.io | 10k/month (not for production) | $5/mo (250k) | Yes | Not documented | No | Active |
| cors.sh | 10k/month, 5GB | $4/mo (500k) | Yes | No (per their own spec) | Yes (MIT, full monorepo) | Active |
| cors.lol | "Unlimited" (rate-limited) | $35 lifetime | No | Not documented | Yes | Active (site dated 2024) |
| corsproxy.dev | 500/day | $5/mo (20k/day) | Yes | Yes, documented | Yes (MIT) | Active |
"Not documented" means the service's own pricing/docs/marketing pages make no mention of blocking private-network or internal targets — not that we tested and found it missing. cors.sh is the exception: its source is public, so "No" there is read from its own committed spec of documented behavior, not an absence of marketing copy. For everyone else, if it matters to you, ask the vendor directly before you rely on it.
What to actually watch for
"Free" is a feature, but so are the things that make a proxy not embarrassing to depend on:
- Does it block private-network targets? An open proxy that will fetch
http://169.254.169.254/is an SSRF bug waiting to be exploited. The proxy's hosting provider gets the blame; you get a side helping of legal letters. corsproxy.dev blocks private-network targets; for any other proxy, check its docs, and if it doesn't say, assume it doesn't. - Does it forward
Authorizationheaders? If yes, anyone can use the proxy to call paid APIs with someone else's bearer token. Better proxies strip them. - Does it have rate limits per identity? Per-IP limits get crushed by NAT (one shared egress IP can be a whole company). Per-key limits are the right granularity.
- Will it be there next month? Volunteer-run proxies disappear regularly. Pick something with a business model that pays for hosting.
For the full security argument, see how a CORS proxy can be abused.
What we'd actually recommend
- You control the upstream. Don't use any proxy. Configure CORS on the upstream. It's correct and free.
- You're in dev and just need it to work. Use your build tool's proxy config. 5 ways covered here.
- You need a managed proxy in production. Pick one that has API keys, per-account rate limits, and a documented security stance. corsproxy.dev is our answer: it's the only one of the seven here that documents what it does with a private-network target, and $5/month for 20,000 requests/day gives you more total quota than any other managed option here, even though cors.sh's $4/month tier is very slightly cheaper per request.
- You can't send your data through anyone else. Self-host. Our Go binary is MIT; cors-anywhere is the other obvious open-source choice but is heavier (Node + lots of features).
Get 500 free requests/day
No credit card. Email-only sign-in. Self-host the same code later if you outgrow it.