Call model APIs from the browser without exposing your provider key
Prototype AI features in the frontend. Proxify forwards the request, adds the CORS headers, and inserts your provider token on the server, so it never ships in your bundle.
Access to fetch at 'https://inference.example.com/v1/generate' from origin 'https://your-app.example.com' has been blocked by CORS policy: No 'Access-Control-Allow-Origin' header is present on the requested resource.
HTTP/2 200
access-control-allow-origin: https://your-app.example.com
x-proxify-ratelimit-remaining: 9999
AI demos stall on two things: CORS and the API key
Some model APIs refuse browser calls outright. Others accept them, but only with a provider token that anyone could read from your JavaScript and spend on your account.
Standing up a server just to forward a request and hide a token slows every prototype down, and it is one more thing to deploy.
How Proxify helps
Configured from the dashboard, enforced on every request.
-
Provider tokens in a vault
Store the token once. Reference it as {{secret.NAME}} in X-Proxify-Upstream-Authorization and Proxify sends it upstream as Authorization.
-
Bound to the right host
Each secret is bound to the hosts it may be sent to, so a token for one provider is never sent anywhere else.
-
Streaming passes through
Server-sent events and other streamed responses are flushed to the browser as they arrive, so text appears while the model is still writing.
-
Quotas and rate limits per key
Cap how many requests a public key can make per month and per second, so a copied demo key has a ceiling.
-
Signed URLs when it matters
Require an expiring HMAC signature on a key, so only requests your own server signed are accepted.
-
Record and replay
Record model responses into a cassette and replay them in demos and tests instead of paying for the same call again.
Example
Keep the token out of the bundle
- Add the token on the dashboard's Secrets page and bind it to the provider's host.
- A secret belongs to one API key; requests made with other keys cannot use it.
- Read streamed output with response.body.getReader() or an EventSource-style parser.
const target = 'https://inference.example.com/v1/generate';
const res = await fetch(`https://api.proxifyedge.com/proxy?url=${encodeURIComponent(target)}`, {
method: 'POST',
headers: {
'X-API-Key': 'pk_your_public_key',
// Replaced on the server with the stored token and sent upstream
// as the Authorization header. The browser never sees the token.
'X-Proxify-Upstream-Authorization': 'Bearer {{secret.MODEL_API_TOKEN}}',
'Content-Type': 'application/json',
},
body: JSON.stringify({ prompt: 'Explain CORS in one sentence.' }),
});
// Streamed responses arrive as the model produces them.
const reader = res.body.getReader();
Questions
Something else? Get in touch or read the docs.
Can visitors see my provider token?
No. The browser only sends the placeholder {{secret.NAME}}. Proxify replaces it on the server, after checking the secret is bound to the host the request is going to.
Does Proxify work with streaming responses?
Yes. Responses streamed as server-sent events, or with no declared length, are flushed to the browser as they arrive rather than buffered.
Is Proxify an AI provider?
No. Proxify forwards your requests to the provider you choose, using your own account and token. Pricing, models and usage terms are the provider’s.
Can someone else spend my AI budget with my public key?
A live key only answers the origins you list, and per-key quotas and rate limits cap what any copy of it can do. For tighter control, require signed URLs on the key.
Use model APIs within each provider's terms, including their rules on client-side use, usage limits and content.