Open source
MIT licensed- Self-host the Go binary anywhere
- No quotas, no API keys, no accounts
- Run alongside your other infra
- One-click deploy: Railway, Render, Fly, Koyeb
- Source on GitHub
Managed relay + open-source runtime
A managed relay for the third-party APIs your frontend has to call — API keys, rate limits, logs, and a dashboard out of the box. Self-host the same runtime when policy or scale requires it.
Fix CORS without shipping a throwaway backend. Free tier — no credit card.
Sign in, create an API key, and start sending requests through the hosted proxy with usage tracking and daily limits.
curl -H "X-API-Key: sk_live_..." \
"https://api.corsproxy.dev/proxy?url=https://api.github.com/users/octocat"
# Browser-friendly form
https://api.corsproxy.dev/proxy?url=https://api.github.com/users/octocat&key=sk_live_...
Create a free account →
Single ~10MB binary. Zero dependencies. Deploys to Railway, Render, Fly, or your own box.
git clone https://github.com/melihbirim/corsproxy
cd corsproxy
go run main.go # listens on :8080
Read the README →
Store a provider key (OpenAI, Notion, Stripe…) on your corsproxy.dev key once. We add it only to requests for the host and path you choose, so it never ships in frontend code. Managed upstream headers →
Give Claude Code, Cursor, and other agents safe API access over Streamable HTTP: SSRF blocked, hard quotas, secrets injected server-side. How it works →
Add ttl=300 to a GET and repeat calls are served from Cloudflare's edge, with an X-Cache: HIT header. Cache entries are private to your key. Pro plan. Caching →
Set or strip headers per request with reqHeaders and resHeaders. Same syntax as corsproxy.io, so switching is copy-paste. Header overrides →
Lock each key to your site's origin (plus localhost for development), requests to private networks and cloud metadata are refused, and upstream cookies are stripped.
Daily limits enforced atomically per account, with X-RateLimit-* headers on every proxied response and an email the day you hit the limit.
Your last 100 calls in the dashboard with status, timing, and size, plus 30 days of history and per-key usage.
GET, POST, PUT, PATCH, DELETE. JSON, images, PDFs, and other files pass through byte-for-byte, up to 10 MB per response.
The proxy runtime is MIT-licensed Go. Self-host it on Railway, Render, Fly, or your own server when policy or scale requires it.
Data export anytime. Deleting your account stops access immediately; data is kept 30 days for abuse investigations, then permanently purged.
ttl) and header overridesWhat the browser is actually doing, why your server "refuses" to respond, and three concrete ways to fix it.
SSRF, credential laundering, bandwidth burn. The honest threat model and the mitigations corsproxy.dev applies.
Vite proxy, webpack dev-server, server-side headers, the disabled-security browser, and a CORS proxy.
Machine-readable contract for every endpoint. Drop into Stoplight, Swagger UI, Insomnia, or a code generator.
openapi.yaml →Import directly. Set api_key and origin and you're calling the proxy and MCP endpoints.
Live health probes of the API worker, marketing site, dashboard, and Cloudflare edge — checked from your network.
corsproxy.dev/status →