Rate limits and quotas on corsproxy.dev, explained
You got a 429. Here's exactly what counts against your quota, when it resets, and how the counter is enforced so you're never charged for someone else's overage — or let through past your own.
What counts as a request
Every authenticated call to /proxy (or /v1/proxy) that passes URL validation counts once, whatever the upstream returns. An upstream 500 and a clean 200 count the same — the meter runs on your request, not on whether the target liked it.
Requests rejected before that point don't count: a missing or invalid key, a malformed target URL, or a target on a private network blocked by SSRF protection.
Requests to account endpoints — /v1/auth/*, /v1/api-keys/*, /v1/usage/* — don't count against your proxy quota. Only actual proxying does.
How the limit is enforced
Your account's daily count lives in a Cloudflare Durable Object — one strongly-consistent counter per account, checked and incremented atomically on every request. That matters more than it sounds: a naive "read count, check, increment" implementation racing two simultaneous requests can let both through even when the first one alone should have hit the cap. A Durable Object serializes those checks, so the 100th request lands right on the limit and the 101st gets a 429, even under concurrent load.
Historical usage — the numbers behind your dashboard charts — is a separate, non-authoritative record in D1. It's what you see in Usage → History; it is not what gates your requests. The Durable Object is the only thing that can say yes or no in real time.
What a 429 looks like
HTTP/1.1 429 Too Many Requests
{
"success": false,
"error": "Rate limit exceeded. Your limit is 500 requests per day. Resets at Tue, 18 Aug 2026 00:00:00 GMT",
"code": "RATE_LIMIT_EXCEEDED"
}
Successful proxy responses carry X-RateLimit-Limit, X-RateLimit-Remaining, X-RateLimit-Used, and X-RateLimit-Reset (Unix seconds), so you can slow down before you hit the wall.
The counter resets at UTC midnight, not on a rolling 24-hour window. If you burn your quota at 11pm UTC, you get it back at midnight — not in 24 hours.
Limits by plan
Free tier is 500 requests/day per account, shared across all its keys. Paid tiers raise the ceiling; see API docs for current numbers, since those change independently of this post. Whatever your plan, the enforcement mechanism above is identical — there's no separate "trust me" path for paid keys, just a higher number.
If you're building something that needs more
Two honest options: request a higher limit (email [email protected] — we'd rather raise your quota than have you work around it), or self-host. The open-source core is the same proxy logic with no built-in ceiling — you set your own limits, or none.
What hitting your limit doesn't do
It doesn't ban your key or flag your account. It's purely a 429 until the counter resets — for every key on the account, since they share one quota. If you're seeing 429s you don't expect, check Usage → History in the dashboard first — the most common cause is a retry loop on the client side quietly multiplying real traffic.