Your game runs in a browser now. So do its API calls.
Unity WebGL builds, Godot web exports and Phaser games make their requests from the player's browser, where CORS applies. ProxifyEdge adds the headers and tunnels WebSockets too.
Access to fetch at 'https://api.example-game.com/leaderboard' from origin 'https://play.your-game.example' has been blocked by CORS policy: No 'Access-Control-Allow-Origin' header is present on the requested resource.
HTTP/2 200
access-control-allow-origin: https://play.your-game.example
x-proxify-ratelimit-remaining: 9999
It works in the editor and fails in the web build
Desktop builds make HTTP requests freely. Exported to the web, the same requests go through the browser, which blocks responses from APIs that don't allow your game's origin.
That covers leaderboards, cloud saves and content loaded at runtime, as well as WebSocket servers that check where a connection comes from.
How ProxifyEdge helps
Configured from the dashboard, enforced on every request.
-
WebSocket tunnel
Connect to /proxy/ws with a wss:// target and ProxifyEdge tunnels the socket, with the same key and origin rules as HTTP.
-
Locked to your game's domain
A live key only answers the origins you list, such as the site or portal your web build is served from.
-
No secrets in the build
Anyone can unpack a web build. Keep server tokens in the vault and send a {{secret.NAME}} placeholder instead.
-
Rate limits per key
Cap requests per second and per month, so a runaway loop or a copied key has a ceiling.
-
Batch requests
Load a level's data from several endpoints in one round trip.
Example
Leaderboard over HTTP, lobby over WebSocket
- In Unity, pass the same URL to UnityWebRequest; in Godot, to HTTPRequest.
- Add the domain your game is served from to the key's allowed origins.
- A WebSocket message larger than the configured request size limit closes the tunnel.
const KEY = 'pk_your_public_key';
// HTTP: fetch the leaderboard.
const board = 'https://api.example-game.com/leaderboard?top=10';
const scores = await fetch(
`https://api.proxifyedge.com/proxy?key=${KEY}&url=${encodeURIComponent(board)}`,
).then((response) => response.json());
// WebSocket: browsers can't set headers on a socket, so the key goes in the URL.
const lobby = 'wss://realtime.example-game.com/lobby';
const socket = new WebSocket(
`wss://api.proxifyedge.com/proxy/ws?key=${KEY}&url=${encodeURIComponent(lobby)}`,
);
Questions
Something else? Get in touch or read the docs.
Does this work with Unity WebGL builds?
Yes, for the HTTP requests your game makes with UnityWebRequest and for WebSocket connections through the tunnel. Point the request at the ProxifyEdge URL instead of calling the API directly.
Can I keep my server token out of the web build?
Yes. Store it in the secrets vault and send X-Proxify-Upstream-Authorization: Bearer {{secret.NAME}}. The real token is inserted on the server.
Can players abuse my key?
They can see it, as with any key in client code. Origin locking stops other sites using it from their pages, and per-key rate limits and quotas cap what anyone can do with a copy.
Is ProxifyEdge a game server?
No. It forwards requests to your own server or a service you use. Game logic and player data stay there.
Use ProxifyEdge with APIs you are allowed to call, within their terms. It is not a way around a platform's rules, anti-cheat systems or access restrictions.