Agents

An MCP server for safe API calls from AI agents

corsproxy.dev now runs a remote MCP server. Connect it to Claude Code, Cursor, or your own agent, and the agent can call third-party APIs through your key without ever seeing the API's secret, without reaching internal addresses, and without running up an unbounded bill.

· ~5 min read · Updated Oct 1, 2026

Agents don't have a CORS problem. They have a secrets problem.

An agent runs on a server or your laptop, not in a browser, so the browser's CORS check never applies to it. What goes wrong when an agent calls an API is different:

These are the same problems a browser app has with third-party APIs, which is what corsproxy.dev was built for.

What the MCP server does

It lives at https://api.corsproxy.dev/mcp and has three tools:

Setup in Claude Code is one command:

claude mcp add --transport http corsproxy https://api.corsproxy.dev/mcp \
  --header "X-API-Key: sk_live_..." \
  --header "Origin: http://localhost:3000"

It authenticates like any server-side call: your corsproxy.dev key plus an origin that key allows (Free keys always allow localhost). Other clients take the same URL and headers in their mcp.json; see the MCP docs.

The server is also listed on the official MCP Registry as dev.corsproxy/mcp, domain-verified, so clients that support registry discovery can find it without the manual add command above.

Keeping the secret out of the model

fetch_url runs through the same proxy as your browser traffic, so a key's managed upstream headers apply. Store the provider secret on the corsproxy.dev key once:

"upstream_rules": [{
  "target_host": "api.openai.com",
  "path_prefix": "/v1/chat/completions",
  "headers": { "Authorization": "Bearer sk-YOUR_OPENAI_KEY" }
}]

Now the agent calls https://api.openai.com/v1/chat/completions through fetch_url, and the proxy adds the Authorization header on the way out. The agent only ever holds your corsproxy.dev key, which is limited to that host and path, so there's no OpenAI key in its context to leak or be tricked into revealing. We walk through the same pattern for browser apps in keeping API keys out of the browser.

Guardrails you get by default

What it doesn't do yet

Try it

Get a free API key, then add the MCP server with the command above. 500 requests/day on Free, 20,000/day on Pro.