Skip to content
For web game developers

Your game runs in a browser now. So do its API calls.

Unity WebGL builds, Godot web exports and Phaser games make their requests from the player's browser, where CORS applies. Proxify adds the headers and tunnels WebSockets too.

Browser console, calling the API directly

Access to fetch at 'https://api.example-game.com/leaderboard' from origin 'https://play.your-game.example' has been blocked by CORS policy: No 'Access-Control-Allow-Origin' header is present on the requested resource.

The same request through Proxify
HTTP/2 200
access-control-allow-origin: https://play.your-game.example
x-proxify-ratelimit-remaining: 9999

It works in the editor and fails in the web build

Desktop builds make HTTP requests freely. Exported to the web, the same requests go through the browser, which blocks responses from APIs that don't allow your game's origin.

That covers leaderboards, cloud saves and content loaded at runtime, as well as WebSocket servers that check where a connection comes from.

How Proxify helps

Configured from the dashboard, enforced on every request.

  • WebSocket tunnel

    Connect to /proxy/ws with a wss:// target and Proxify tunnels the socket, with the same key and origin rules as HTTP.

  • Locked to your game's domain

    A live key only answers the origins you list, such as the site or portal your web build is served from.

  • No secrets in the build

    Anyone can unpack a web build. Keep server tokens in the vault and send a {{secret.NAME}} placeholder instead.

  • Rate limits per key

    Cap requests per second and per month, so a runaway loop or a copied key has a ceiling.

  • Batch requests

    Load a level's data from several endpoints in one round trip.

Example

Leaderboard over HTTP, lobby over WebSocket

  • In Unity, pass the same URL to UnityWebRequest; in Godot, to HTTPRequest.
  • Add the domain your game is served from to the key's allowed origins.
  • A WebSocket message larger than the configured request size limit closes the tunnel.
Proxy reference
network.js
const KEY = 'pk_your_public_key';

// HTTP: fetch the leaderboard.
const board = 'https://api.example-game.com/leaderboard?top=10';
const scores = await fetch(
  `https://api.proxifyedge.com/proxy?key=${KEY}&url=${encodeURIComponent(board)}`,
).then((response) => response.json());

// WebSocket: browsers can't set headers on a socket, so the key goes in the URL.
const lobby = 'wss://realtime.example-game.com/lobby';
const socket = new WebSocket(
  `wss://api.proxifyedge.com/proxy/ws?key=${KEY}&url=${encodeURIComponent(lobby)}`,
);

Questions

Something else? Get in touch or read the docs.

Does this work with Unity WebGL builds?

Yes, for the HTTP requests your game makes with UnityWebRequest and for WebSocket connections through the tunnel. Point the request at the Proxify URL instead of calling the API directly.

Can I keep my server token out of the web build?

Yes. Store it in the secrets vault and send X-Proxify-Upstream-Authorization: Bearer {{secret.NAME}}. The real token is inserted on the server.

Can players abuse my key?

They can see it, as with any key in client code. Origin locking stops other sites using it from their pages, and per-key rate limits and quotas cap what anyone can do with a copy.

Is Proxify a game server?

No. It forwards requests to your own server or a service you use. Game logic and player data stay there.

Use Proxify with APIs you are allowed to call, within their terms. It is not a way around a platform's rules, anti-cheat systems or access restrictions.

Make the request your browser was blocking.

Create an account, lock your key to your site, and send your first request through Proxify.

Are you sure?