Blog
Build for the browser without the workarounds
Practical guides to CORS, API keys in frontend code, rate limits, signed URLs, WebSockets and running code at the edge.
Subscribe via RSS-
Architecture
API gateway vs reverse proxy vs CORS proxy: what each one does
API gateway vs reverse proxy vs CORS proxy compared: who each serves, what it does, where they overlap, and how to choose the right one for your architecture.
6 min read Read -
Rate limiting
API rate limiting for frontend developers: 429s and Retry-After
Understand API rate limiting from the browser: what 429 and Retry-After mean, how to read rate-limit headers cross-origin, and how to retry with backoff and jitter.
6 min read Read -
Performance
Batching API requests from the browser to cut round trips
When batching API requests helps, how to express dependencies between calls, how to handle partial failures, and the limits that keep a batch from hurting you.
5 min read Read -
AI
Call the OpenAI API from the browser without leaking your key
How to call the OpenAI API and other LLM APIs from a web app without exposing your key: a server route, streaming, cost limits and a gateway.
6 min read Read -
No-code
Calling APIs from no-code tools: Webflow, Bubble and Framer
Why API calls fail with CORS errors in no-code tools, which calls run in the browser and which on a server, and how to keep API keys out of your published site.
6 min read Read -
CORS
CORS preflight requests explained: when and why OPTIONS happens
What triggers a CORS preflight request, how the browser and server negotiate it, how Access-Control-Max-Age caches it, and how to fix the failures you'll see.
6 min read Read -
CORS
CORS with credentials: cookies, credentials: 'include' and the wildcard
Why cross-origin cookies need credentials: 'include', Access-Control-Allow-Credentials and an exact origin, how SameSite affects them, and why Vary matters.
5 min read Read -
CORS
CORS, CSP, CORP and COEP compared: browser security headers
CORS, CSP, CORP, COEP and COOP each answer a different question. Learn who sends each header, what it protects, and how they interact when a request fails.
5 min read Read -
CORS
Debugging CORS errors step by step in Chrome and Firefox DevTools
A repeatable routine for debugging CORS errors: read the console, find the preflight in the Network panel, compare headers, and reproduce the request with curl.
5 min read Read -
CORS
Fixing CORS errors in React and Vite, in dev and in production
Fix CORS errors in a React app built with Vite: set up server.proxy for development, understand why it vanishes in production, and choose a production fix.
5 min read Read -
CORS
Fixing CORS errors in SvelteKit and Astro
Where SvelteKit and Astro code runs decides whether CORS applies. Fix CORS errors with server endpoints, load functions, middleware, dev proxies or a proxy.
5 min read Read -
CORS
Fixing CORS errors in Vue and Nuxt: dev proxies, server routes and more
How to fix CORS errors in Vue and Nuxt: Vite's dev proxy for Vue, Nuxt server routes, routeRules proxies and Nitro devProxy, plus what works on static hosting.
5 min read Read -
CORS
How to fix 'No Access-Control-Allow-Origin header is present'
Read the exact CORS error, find out whose server has to change, and pick the right fix: configure the API, add a backend, use a dev proxy or a CORS proxy.
5 min read Read -
API keys
Publishable API keys: designing keys that are safe in a browser
What makes a publishable API key safe to ship in a browser bundle: scoped capabilities, origin allowlists and their limits, quotas, test keys and rotation.
7 min read Read -
Testing
Record and replay: deterministic API mocks for tests and demos
Use the record and replay pattern to turn real API responses into fixtures: how matching works, how to keep secrets out of recordings, and when to re-record.
5 min read Read -
Security
Signed URLs explained: HMAC signatures, expiry and replay protection
How signed URLs work: HMAC signatures, canonical forms, expiry, method binding, nonces and replay protection, with working signing and verification code.
6 min read Read -
Security
SSRF explained: why every proxy needs a guard against internal IPs
What server-side request forgery is, how attackers reach internal services and cloud metadata through URL fetchers, and the defenses that actually hold up.
6 min read Read -
Edge
WebAssembly at the edge: transform API traffic without a server
How WebAssembly modules can rewrite API requests and responses inline: sandboxing, a minimal ABI, time and memory budgets, and choosing fail-open or fail-closed.
5 min read Read -
WebSockets
WebSockets and CORS: what the browser checks and how to proxy them
CORS does not apply to WebSockets. Learn what the Origin header does, how servers must check it, how to authenticate a socket, and how to proxy one safely.
5 min read Read -
API keys
You can't hide an API key in frontend code. Do this instead
Why environment variables, bundlers and obfuscation can't hide an API key in frontend code, and the three patterns that actually keep secrets off the client.
6 min read Read -
CORS
How to fix CORS errors in Next.js
Route handlers, rewrites, configuring the API, or a CORS proxy: which fix to use for an Access-Control-Allow-Origin error in a Next.js app, with code for each.
3 min read Read