Managed relay + open-source runtime

Ship browser integrations
without the proxy work.

A managed relay for the third-party APIs your frontend has to call — API keys, rate limits, logs, and a dashboard out of the box. Self-host the same runtime when policy or scale requires it.

Fix CORS without shipping a throwaway backend. Free tier — no credit card.

Managed

Use the hosted API

Sign in, create an API key, and start sending requests through the hosted proxy with usage tracking and daily limits.

curl -H "X-API-Key: sk_live_..." \
  "https://api.corsproxy.dev/proxy?url=https://api.github.com/users/octocat"

# Browser-friendly form
https://api.corsproxy.dev/proxy?url=https://api.github.com/users/octocat&key=sk_live_...
Create a free account →
Self-hosted

Run the Go binary

Single ~10MB binary. Zero dependencies. Deploys to Railway, Render, Fly, or your own box.

git clone https://github.com/melihbirim/corsproxy
cd corsproxy
go run main.go     # listens on :8080
Read the README →

What you get

Keep API secrets out of the browser

Store a provider key (OpenAI, Notion, Stripe…) on your corsproxy.dev key once. We add it only to requests for the host and path you choose, so it never ships in frontend code. Managed upstream headers →

Remote MCP server for AI agents

Give Claude Code, Cursor, and other agents safe API access over Streamable HTTP: SSRF blocked, hard quotas, secrets injected server-side. How it works →

Edge caching

Add ttl=300 to a GET and repeat calls are served from Cloudflare's edge, with an X-Cache: HIT header. Cache entries are private to your key. Pro plan. Caching →

Header overrides

Set or strip headers per request with reqHeaders and resHeaders. Same syntax as corsproxy.io, so switching is copy-paste. Header overrides →

Locked down by default

Lock each key to your site's origin (plus localhost for development), requests to private networks and cloud metadata are refused, and upstream cookies are stripped.

Exact quotas, no surprises

Daily limits enforced atomically per account, with X-RateLimit-* headers on every proxied response and an email the day you hit the limit.

Logs and usage

Your last 100 calls in the dashboard with status, timing, and size, plus 30 days of history and per-key usage.

Any request, any file

GET, POST, PUT, PATCH, DELETE. JSON, images, PDFs, and other files pass through byte-for-byte, up to 10 MB per response.

Open source core

The proxy runtime is MIT-licensed Go. Self-host it on Railway, Render, Fly, or your own server when policy or scale requires it.

Privacy built in

Data export anytime. Deleting your account stops access immediately; data is kept 30 days for abuse investigations, then permanently purged.

Two ways to use it

Open source

MIT licensed
  • Self-host the Go binary anywhere
  • No quotas, no API keys, no accounts
  • Run alongside your other infra
  • One-click deploy: Railway, Render, Fly, Koyeb
  • Source on GitHub
View on GitHub

From the blog

All posts →
Tutorial

Why am I getting a CORS error?

What the browser is actually doing, why your server "refuses" to respond, and three concrete ways to fix it.

Security

How a CORS proxy can be abused

SSRF, credential laundering, bandwidth burn. The honest threat model and the mitigations corsproxy.dev applies.

How-to

5 ways to fix CORS in development

Vite proxy, webpack dev-server, server-side headers, the disabled-security browser, and a CORS proxy.

Developer tools

All docs →

Start free, go Pro for $5/month

Free covers evaluation and small projects: 500 requests/day. Pro is $5/month for 20,000 requests/day, unlimited API keys, and unlimited managed upstream headers. Upgrade from your dashboard, cancel anytime. Need more? Enterprise is arranged through the dashboard's contact form.