Use Proxify from extensions and userscripts
Content scripts and userscripts run inside someone else’s page, so the browser holds their requests to that page’s CORS rules. Proxify gets those requests through.
There is no Proxify browser extension
When you need it
-
Proxify helps
Content scripts
In Chromium browsers, a content script’s requests follow the CORS rules of the page it runs on. Send them through Proxify with a live key whose allowed origins include that page’s origin.
-
Proxify helps
Userscripts using fetch
A userscript that calls fetch behaves like the page it is injected into. Route the request through Proxify and allow the page’s origin on your key.
-
Not needed
Extension pages and service workers
With host permissions for the API you are calling, the browser does not apply CORS to an extension’s own pages or service worker, so you do not need a proxy there.
From a content script
On your key’s settings, add the origin of each site the script runs on, for example
https://news.example.com.
// content-script.js: runs on https://news.example.com
const target = 'https://api.example.org/v1/headlines';
const response = await fetch(
`https://api.proxifyedge.com/proxy?url=${encodeURIComponent(target)}`,
{ headers: { 'X-API-Key': 'pk_your_public_key' } },
);
const headlines = await response.json();
From a userscript
The same applies to Tampermonkey or Violentmonkey scripts that use fetch.
Scripts that use GM_xmlhttpRequest already bypass CORS.
// ==UserScript==
// @name Show headlines
// @match https://news.example.com/*
// @grant none
// ==/UserScript==
const target = 'https://api.example.org/v1/headlines';
fetch(`https://api.proxifyedge.com/proxy?url=${encodeURIComponent(target)}`, {
headers: { 'X-API-Key': 'pk_your_public_key' },
})
.then((response) => response.json())
.then((headlines) => console.log(headlines));
Keep upstream credentials out of the script
Anything you ship in an extension or userscript can be read by its users. Store the upstream API’s token in the secrets vault instead, and reference it by name. Proxify substitutes it on the server, only for the hosts you allow.
Live keys accept only http and https origins. Use a test key while you develop.
fetch(`https://api.proxifyedge.com/proxy?url=${encodeURIComponent('https://api.example.org/v1/private')}`, {
headers: {
'X-API-Key': 'pk_your_public_key',
// Sent upstream as "Authorization: Bearer <value of the UPSTREAM_TOKEN secret>".
'X-Proxify-Upstream-Authorization': 'Bearer {{secret.UPSTREAM_TOKEN}}',
},
});