Skip to content

Use Proxify from extensions and userscripts

Content scripts and userscripts run inside someone else’s page, so the browser holds their requests to that page’s CORS rules. Proxify gets those requests through.

There is no Proxify browser extension

When you need it

  • Proxify helps

    Content scripts

    In Chromium browsers, a content script’s requests follow the CORS rules of the page it runs on. Send them through Proxify with a live key whose allowed origins include that page’s origin.

  • Proxify helps

    Userscripts using fetch

    A userscript that calls fetch behaves like the page it is injected into. Route the request through Proxify and allow the page’s origin on your key.

  • Not needed

    Extension pages and service workers

    With host permissions for the API you are calling, the browser does not apply CORS to an extension’s own pages or service worker, so you do not need a proxy there.

From a content script

On your key’s settings, add the origin of each site the script runs on, for example https://news.example.com.

content-script.js
// content-script.js: runs on https://news.example.com
const target = 'https://api.example.org/v1/headlines';

const response = await fetch(
  `https://api.proxifyedge.com/proxy?url=${encodeURIComponent(target)}`,
  { headers: { 'X-API-Key': 'pk_your_public_key' } },
);
const headlines = await response.json();

From a userscript

The same applies to Tampermonkey or Violentmonkey scripts that use fetch. Scripts that use GM_xmlhttpRequest already bypass CORS.

headlines.user.js
// ==UserScript==
// @name        Show headlines
// @match       https://news.example.com/*
// @grant       none
// ==/UserScript==

const target = 'https://api.example.org/v1/headlines';
fetch(`https://api.proxifyedge.com/proxy?url=${encodeURIComponent(target)}`, {
  headers: { 'X-API-Key': 'pk_your_public_key' },
})
  .then((response) => response.json())
  .then((headlines) => console.log(headlines));

Keep upstream credentials out of the script

Anything you ship in an extension or userscript can be read by its users. Store the upstream API’s token in the secrets vault instead, and reference it by name. Proxify substitutes it on the server, only for the hosts you allow.

Live keys accept only http and https origins. Use a test key while you develop.

with-secret.js
fetch(`https://api.proxifyedge.com/proxy?url=${encodeURIComponent('https://api.example.org/v1/private')}`, {
  headers: {
    'X-API-Key': 'pk_your_public_key',
    // Sent upstream as "Authorization: Bearer <value of the UPSTREAM_TOKEN secret>".
    'X-Proxify-Upstream-Authorization': 'Bearer {{secret.UPSTREAM_TOKEN}}',
  },
});

Are you sure?