Call any API from the browser. Safely.
One origin-locked key to fix CORS errors, keep API keys secret, sign every URL, rate-limit per key, proxy WebSockets, run WebAssembly
ProxifyEdge sits between your frontend and the APIs it calls. It adds the CORS headers, injects secrets on the server, checks signatures and enforces per-key limits, so you ship the feature instead of a backend.
- No card required to sign up
- Works with any HTTP API
- Keys locked to your origins
- OpenAI
- Anthropic
- Stripe
- GitHub
- Supabase
- Firebase
- Airtable
- Notion
- Shopify
- Hugging Face
- CoinGecko
- Open-Meteo
- Any HTTPS API
More than a CORS proxy
Everything between your frontend and the API
The parts of an API gateway a browser app actually needs, set up from the dashboard.
-
CORS, handled
The browser blocks responses an API never meant to share. ProxifyEdge returns them with the right headers and answers preflight for you.
Blocked by CORS policy: No 'Access-Control-Allow-Origin' header…
200 OK · access-control-allow-origin: your-app.example.com
-
Origin-locked keys
Live keys answer only your origins. Test keys answer any while you develop.
- https://your-app.example.com
- https://copycat.example
-
Secrets vault
Reference a provider token by name. It is added on the server, only for the hosts you allow, and never reaches the browser.
X-Proxify-Upstream-Authorization: Bearer {{secret.OPENAI_KEY}}
→ Authorization: Bearer ••••••••••••
-
Signed URLs
Require an HMAC signature and an expiry on every request, so a copied link stops working when it should.
/proxy?url=…&exp=1791200000&sig=8f2c…a91
-
Quotas and rate limits
Monthly quotas and per-second limits per key, reported on every response.
-
WebSockets and batches
Tunnel WebSockets under the same origin rules, or send up to 20 requests in one round trip.
-
Edge modules and replay
Rewrite traffic with WebAssembly, or record responses and replay them for demos and tests.
Drop-in
Keep your fetch call. Change one URL.
No SDK and no server of your own. The upstream status and headers come back as the API sent them, with the CORS headers your browser needs added.
Read the proxy referenceconst target = 'https://api.github.com/repos/withastro/astro';
const response = await fetch(
`https://api.proxifyedge.com/proxy?url=${encodeURIComponent(target)}`,
{ headers: { 'X-API-Key': 'pk_your_public_key' } },
);
const repo = await response.json();
// The provider token lives in your ProxifyEdge vault, not in this bundle.
const response = await fetch(
`https://api.proxifyedge.com/proxy?url=${encodeURIComponent('https://api.openai.com/v1/chat/completions')}`,
{
method: 'POST',
headers: {
'X-API-Key': 'pk_your_public_key',
'Content-Type': 'application/json',
'X-Proxify-Upstream-Authorization': 'Bearer {{secret.OPENAI_KEY}}',
},
body: JSON.stringify({ model: 'gpt-4o-mini', messages }),
},
);
curl "https://api.proxifyedge.com/proxy?url=https://api.github.com/repos/withastro/astro" \
-H "X-API-Key: pk_your_public_key" -i
# HTTP/2 200
# access-control-allow-origin: https://your-app.example.com
# x-proxify-ratelimit-remaining: 9999
How it works
Working in three steps
-
1
Create an account
Sign up and get a public API key straight away. No card is needed to sign up.
-
2
Lock the key to your site
List the origins allowed to use it. Requests from anywhere else are refused, so the key is safe in a browser bundle.
-
3
Send requests through it
Prefix the URL with api.proxifyedge.com/proxy and add your key. Secrets, signatures and limits apply on the way through.
Secure by default
A proxy that can't be turned against you
An open proxy is an attack surface. ProxifyEdge refuses internal addresses, keeps secrets write-only and records what changes on your account.
-
SSRF guard
Private, loopback and cloud-metadata addresses are refused, after every redirect.
-
Encrypted secrets
Upstream credentials are stored encrypted (AES-256-GCM) and can never be read back.
-
Origin enforcement
Live keys answer only the origins you list; preflight is answered without touching your quota.
-
Audit trail
Sign-ins, failed attempts, password changes and administrator actions are recorded with time, address and client.