Ship client demos on real APIs, without waiting on a backend
Prototype against the client's APIs from the browser on day one. Keep their credentials out of the code, and make the demo independent of the network on the day.
Access to fetch at 'https://api.client-example.com/v2/orders' from origin 'https://demo.your-agency.example' has been blocked by CORS policy: No 'Access-Control-Allow-Origin' header is present on the requested resource.
HTTP/2 200
access-control-allow-origin: https://demo.your-agency.example
x-proxify-ratelimit-remaining: 9999
Demos depend on things you don't control
Front-end prototypes call the client's APIs, and those APIs rarely allow your preview domain. Getting their CORS settings changed means a ticket in someone else's queue.
Meanwhile the client's credentials end up in a demo bundle, and an upstream outage on presentation day takes the whole demo down with it.
How ProxifyEdge helps
Configured from the dashboard, enforced on every request.
-
Client credentials in a vault
Store the client's API token as a secret bound to their API host. It is inserted on the server and never appears in the demo's code.
-
Locked to the demo domain
A live key only answers the origins you list, such as the staging domain you share with the client.
-
Replay on demo day
Record real responses during rehearsal, then switch the key to replay so the demo is served from the recording without calling upstream.
-
Requests that expire
Turn on required signatures and every request needs an expiring signature, so a forwarded link stops working when it should.
-
Batch requests
Fetch data for a screen from up to 20 endpoints in one round trip, each with its own status.
How it fits your workflow
-
Store the client token
Add it as a secret bound to the client's API host.
-
Lock the key
List the staging domain the client will open.
-
Record during rehearsal
Set the key to record mode and click through the demo.
-
Present in replay mode
Switch to replay; the demo no longer depends on the upstream API.
Example
Record now, replay on the day
- Replay mode serves only from the cassette: a request that was never recorded fails rather than calling upstream.
- Switch a key's mode on the Replay page in the dashboard, with no code change.
- Recordings belong to one API key and are listed per cassette.
const target = 'https://api.client-example.com/v2/orders';
// Rehearsal: the key is in record mode, so each response is saved to the
// "client-demo" cassette. Demo day: switch the key to replay mode and the
// same call is served from the recording, without calling the client's API.
const res = await fetch(`https://api.proxifyedge.com/proxy?url=${encodeURIComponent(target)}`, {
headers: {
'X-API-Key': 'pk_your_public_key',
'X-Proxify-Cassette': 'client-demo',
'X-Proxify-Upstream-Authorization': 'Bearer {{secret.CLIENT_API_TOKEN}}',
},
});
Questions
Something else? Get in touch or read the docs.
Will the client's token appear in the demo code?
No. The code only contains the placeholder {{secret.NAME}}. ProxifyEdge replaces it on the server, and only for requests going to the hosts the secret is bound to.
What if the client's API is down during the presentation?
Record the responses beforehand and present with the key in replay mode. Recorded requests are answered from the cassette without contacting the API.
How do signed requests work?
With required signatures on, each request needs an expiry time and an HMAC signature made with the key's signing secret. You sign on your side, so the signing secret never ships to the browser.
Can the demo become the production app?
Yes. The same keys, origin rules and vault apply in production. Switch replay off, list the production origins on a live key, and keep going.