Proxify

A CORS proxy you can run yourself.

Call any API from the browser without the cross-origin error. Unlike a hosted proxy, Proxify runs on your own infrastructure — with a WAF, SSRF protection and per-key origin pinning in front of it.

Try it

select fields projects the response server-side, so only the fields you asked for cross the network. Watch the byte count.

Press Send to make a real request through this server.

Batch — many targets, one round trip

Five APIs normally cost five round trips and five preflights. Here they cost one of each, fanned out concurrently, so the total is the slowest upstream rather than the sum.

Comma-separate the URLs, then press Send batch.

Then use it

fetch("https://api.proxifyedge.com/proxy?url=" + encodeURIComponent(target), {
  headers: { "X-API-Key": "pk_your_key" }
})

A live key only works from an origin you have registered, so it is safe to ship in a browser bundle — page script cannot forge the Origin header.

Keep your upstream keys out of the browser

fetch(proxyUrl, {
  headers: {
    "X-API-Key": "pk_your_key",
    "X-Proxify-Upstream-Authorization": "Bearer {{secret.STRIPE}}"
  }
})

Store the real credential once against your key. Proxify substitutes it on the way out; it never reaches the page.