
Managed CORS proxy with API keys, rate limits, and SSRF protection, or self-host the open-source Go runtime for free.
A startup from The United Kingdom.
This page is designed to help you find out whether CorsProxy.dev is good and if it is the right choice for you.
corsproxy.dev adds CORS headers to any API response so browser frontends can call third-party APIs directly, without building and running your own proxy.
Hosted: Sign up, create an API key, start sending requests. Per-key rate limits, request logs, a dashboard, and a daily quota on the free plan, no credit card required. Pro plan adds edge caching and managed upstream headers (store a provider secret like an OpenAI or Stripe key on your corsproxy.dev key once, instead of shipping it in frontend code).
Self-hosted: The same proxy is a single ~10MB Go binary with zero dependencies. Deploy to Railway, Render, Fly.io, Koyeb, or your own box with one click.
Security-first by default: blocks requests to private IP ranges, loopback, link-local, and cloud metadata endpoints (SSRF protection), even with no configuration, most public CORS proxies don't do this at all.
For AI agents: a remote MCP server (Streamable HTTP) lets Claude Code, Cursor, and other agents call third-party APIs through your key without the agent ever seeing the upstream secret.
Listed in
It's a managed CORS proxy that blocks requests to private IPs, loopback, and cloud metadata endpoints (SSRF protection) by default — most CORS proxies don't do this at all, hosted or self-hosted. The hosted API and the self-hosted binary run the same open-source Go core, so you can start on the free managed tier and move to self-hosting later without changing how you call it. It also runs a remote MCP server, so AI agents (Claude Code, Cursor) can call third-party APIs through your key without ever seeing the upstream secret.
Most free CORS proxies (corsproxy.io, allorigins, cors-anywhere) are unmanaged public relays with no auth, no logs, and no SSRF protection — fine for a demo, risky for production. CorsProxy.dev gives you per-key auth, rate limits, request logs, and a dashboard on a free tier, plus an open-source self-host path (MIT) if you'd rather not depend on a hosted service at all.
Go (self-hosted / open-source core), TypeScript on Cloudflare Workers (hosted SaaS), Cloudflare KV, D1, and Durable Objects for rate limiting.
Frontend and full-stack developers who need their browser app to call a third-party API that doesn't send CORS headers — indie hackers and small teams shipping fast without standing up a backend just to proxy one API call, plus developers wiring AI agents up to external APIs.
We have collected here some useful links to help you find out if CorsProxy.dev is good.
Check the traffic stats of CorsProxy.dev on SimilarWeb. The key metrics to look for are: monthly visits, average visit duration, pages per visit, and traffic by country. Moreoever, check the traffic sources. For example "Direct" traffic is a good sign.
Check the "Domain Rating" of CorsProxy.dev on Ahrefs. The domain rating is a measure of the strength of a website's backlink profile on a scale from 0 to 100. It shows the strength of CorsProxy.dev's backlink profile compared to the other websites. In most cases a domain rating of 60+ is considered good and 70+ is considered very good.
Check the "Domain Authority" of CorsProxy.dev on MOZ. A website's domain authority (DA) is a search engine ranking score that predicts how well a website will rank on search engine result pages (SERPs). It is based on a 100-point logarithmic scale, with higher scores corresponding to a greater likelihood of ranking. This is another useful metric to check if a website is good.
The latest comments about CorsProxy.dev on Reddit. This can help you find out how popualr the product is and what people think about it.
Do you know an article comparing CorsProxy.dev to other products?
Suggest a link to a post with product alternatives.
Is CorsProxy.dev good? This is an informative page that will help you find out. Moreover, you can review and discuss CorsProxy.dev here. The primary details have been verified within the last quarter. So they could be considered up to date. If you think we are missing something, please use the means on this page to comment or suggest changes. All reviews and comments are highly encouranged and appreciated as they help everyone in the community to make an informed choice. Please always be kind and objective when evaluating a product and sharing your opinion.