Skip to content
For AI and LLM apps

Call model APIs from the browser without exposing your provider key

Prototype AI features in the frontend. Proxify forwards the request, adds the CORS headers, and inserts your provider token on the server, so it never ships in your bundle.

Browser console, calling the API directly

Access to fetch at 'https://inference.example.com/v1/generate' from origin 'https://your-app.example.com' has been blocked by CORS policy: No 'Access-Control-Allow-Origin' header is present on the requested resource.

The same request through Proxify
HTTP/2 200
access-control-allow-origin: https://your-app.example.com
x-proxify-ratelimit-remaining: 9999

AI demos stall on two things: CORS and the API key

Some model APIs refuse browser calls outright. Others accept them, but only with a provider token that anyone could read from your JavaScript and spend on your account.

Standing up a server just to forward a request and hide a token slows every prototype down, and it is one more thing to deploy.

How Proxify helps

Configured from the dashboard, enforced on every request.

  • Provider tokens in a vault

    Store the token once. Reference it as {{secret.NAME}} in X-Proxify-Upstream-Authorization and Proxify sends it upstream as Authorization.

  • Bound to the right host

    Each secret is bound to the hosts it may be sent to, so a token for one provider is never sent anywhere else.

  • Streaming passes through

    Server-sent events and other streamed responses are flushed to the browser as they arrive, so text appears while the model is still writing.

  • Quotas and rate limits per key

    Cap how many requests a public key can make per month and per second, so a copied demo key has a ceiling.

  • Signed URLs when it matters

    Require an expiring HMAC signature on a key, so only requests your own server signed are accepted.

  • Record and replay

    Record model responses into a cassette and replay them in demos and tests instead of paying for the same call again.

Example

Keep the token out of the bundle

  • Add the token on the dashboard's Secrets page and bind it to the provider's host.
  • A secret belongs to one API key; requests made with other keys cannot use it.
  • Read streamed output with response.body.getReader() or an EventSource-style parser.
Proxy reference
generate.ts
const target = 'https://inference.example.com/v1/generate';

const res = await fetch(`https://api.proxifyedge.com/proxy?url=${encodeURIComponent(target)}`, {
  method: 'POST',
  headers: {
    'X-API-Key': 'pk_your_public_key',
    // Replaced on the server with the stored token and sent upstream
    // as the Authorization header. The browser never sees the token.
    'X-Proxify-Upstream-Authorization': 'Bearer {{secret.MODEL_API_TOKEN}}',
    'Content-Type': 'application/json',
  },
  body: JSON.stringify({ prompt: 'Explain CORS in one sentence.' }),
});

// Streamed responses arrive as the model produces them.
const reader = res.body.getReader();

Questions

Something else? Get in touch or read the docs.

Can visitors see my provider token?

No. The browser only sends the placeholder {{secret.NAME}}. Proxify replaces it on the server, after checking the secret is bound to the host the request is going to.

Does Proxify work with streaming responses?

Yes. Responses streamed as server-sent events, or with no declared length, are flushed to the browser as they arrive rather than buffered.

Is Proxify an AI provider?

No. Proxify forwards your requests to the provider you choose, using your own account and token. Pricing, models and usage terms are the provider’s.

Can someone else spend my AI budget with my public key?

A live key only answers the origins you list, and per-key quotas and rate limits cap what any copy of it can do. For tighter control, require signed URLs on the key.

Use model APIs within each provider's terms, including their rules on client-side use, usage limits and content.

Make the request your browser was blocking.

Create an account, lock your key to your site, and send your first request through Proxify.

Are you sure?