Skip to content
The API gateway for browser apps

Call any API from the browser. Safely.

One origin-locked key to fix CORS errors, keep API keys secret, sign every URL, rate-limit per key, proxy WebSockets, run WebAssembly

ProxifyEdge sits between your frontend and the APIs it calls. It adds the CORS headers, injects secrets on the server, checks signatures and enforces per-key limits, so you ship the feature instead of a backend.

  • No card required to sign up
  • Works with any HTTP API
  • Keys locked to your origins
your-app.example.com → api.proxifyedge.com
How a request flows through ProxifyEdge Your browser app sends a request to ProxifyEdge, which checks the origin, injects secrets, verifies signatures and applies rate limits before calling the API and returning the response with CORS headers. fetch() Your app ProxifyEdge Origin allowed Secret injected Signature valid Rate limit OK OpenAI Stripe Any API
200 OK · access-control-allow-origin: your-app.example.com x-proxify-ratelimit-remaining: 9999
  • OpenAI
  • Anthropic
  • Stripe
  • GitHub
  • Supabase
  • Firebase
  • Airtable
  • Notion
  • Shopify
  • Hugging Face
  • Reddit
  • CoinGecko
  • Open-Meteo
  • Any HTTPS API

More than a CORS proxy

Everything between your frontend and the API

The parts of an API gateway a browser app actually needs, set up from the dashboard.

  • CORS, handled

    The browser blocks responses an API never meant to share. ProxifyEdge returns them with the right headers and answers preflight for you.

    Blocked by CORS policy: No 'Access-Control-Allow-Origin' header…

    200 OK · access-control-allow-origin: your-app.example.com

  • Origin-locked keys

    Live keys answer only your origins. Test keys answer any while you develop.

    • https://your-app.example.com
    • https://copycat.example
  • Secrets vault

    Reference a provider token by name. It is added on the server, only for the hosts you allow, and never reaches the browser.

    X-Proxify-Upstream-Authorization: Bearer {{secret.OPENAI_KEY}}

    → Authorization: Bearer ••••••••••••

  • Signed URLs

    Require an HMAC signature and an expiry on every request, so a copied link stops working when it should.

    /proxy?url=…&exp=1791200000&sig=8f2c…a91

  • Quotas and rate limits

    Monthly quotas and per-second limits per key, reported on every response.

  • WebSockets and batches

    Tunnel WebSockets under the same origin rules, or send up to 20 requests in one round trip.

  • Edge modules and replay

    Rewrite traffic with WebAssembly, or record responses and replay them for demos and tests.

Drop-in

Keep your fetch call. Change one URL.

No SDK and no server of your own. The upstream status and headers come back as the API sent them, with the CORS headers your browser needs added.

Read the proxy reference
app.js
const target = 'https://api.github.com/repos/withastro/astro';

const response = await fetch(
  `https://api.proxifyedge.com/proxy?url=${encodeURIComponent(target)}`,
  { headers: { 'X-API-Key': 'pk_your_public_key' } },
);

const repo = await response.json();

How it works

Working in three steps

  1. 1

    Create an account

    Sign up and get a public API key straight away. No card is needed to sign up.

  2. 2

    Lock the key to your site

    List the origins allowed to use it. Requests from anywhere else are refused, so the key is safe in a browser bundle.

  3. 3

    Send requests through it

    Prefix the URL with api.proxifyedge.com/proxy and add your key. Secrets, signatures and limits apply on the way through.

Secure by default

A proxy that can't be turned against you

An open proxy is an attack surface. ProxifyEdge refuses internal addresses, keeps secrets write-only and records what changes on your account.

  • SSRF guard

    Private, loopback and cloud-metadata addresses are refused, after every redirect.

  • Encrypted secrets

    Upstream credentials are stored encrypted (AES-256-GCM) and can never be read back.

  • Origin enforcement

    Live keys answer only the origins you list; preflight is answered without touching your quota.

  • Audit trail

    Sign-ins, failed attempts, password changes and administrator actions are recorded with time, address and client.

Ship the feature you were blocked on.

Create an account, lock your key to your site, and make your first request in minutes.

Are you sure?