Connect your no-code site to any API by changing one URL
When custom code in your site builder calls an API from the visitor's browser, CORS gets in the way. Point the request at Proxify instead, with no server to run.
Access to fetch at 'https://api.example.com/products' from origin 'https://your-site.webflow.io' has been blocked by CORS policy: No 'Access-Control-Allow-Origin' header is present on the requested resource.
HTTP/2 200
access-control-allow-origin: https://your-site.webflow.io
x-proxify-ratelimit-remaining: 9999
Custom code runs in the browser, and the browser checks CORS
Site builders let you embed code that fetches live data, but that code runs on your visitor's device. If the API does not allow your site's origin, the browser blocks the response and the embed shows nothing.
Embeds also tempt you to paste API tokens into page code, where anyone can read them with View Source.
How Proxify helps
Configured from the dashboard, enforced on every request.
-
Works from a plain URL
Pass your public key as ?key= and the target as ?url=. Anything that can fetch a URL can use Proxify, with no custom headers.
-
Locked to your site
Add your published domain, and your builder's preview domain, to the key's allowed origins. Other sites cannot use it.
-
Tokens out of your page code
Keep API tokens in the secrets vault and refer to them as {{secret.NAME}} in a header. They are inserted on the server.
-
Usage you can see
See this month's requests in the dashboard, with per-key quotas and rate limits so an embed cannot run away with your plan.
How it fits your workflow
-
1
Create an account
Copy your API key when it is shown.
-
2
Allow your domains
Add your live domain and your builder's preview domain to the key.
-
3
Swap the URL
Replace the API URL in your embed with the Proxify URL.
-
4
Publish
The embed now loads live data on your published site.
Example
An embed that shows live data
- Paste this into your builder's custom code or embed block.
- Add your site's domain to the key's allowed origins first, or the browser will still refuse the response.
- A public key is visible to visitors wherever you put it; the origin lock and quotas are what protect it.
<p>Products in stock: <span id="count">…</span></p>
<script type="module">
const target = 'https://api.example.com/products';
const url = 'https://api.proxifyedge.com/proxy?key=pk_your_public_key&url=' + encodeURIComponent(target);
const products = await fetch(url).then((response) => response.json());
document.querySelector('#count').textContent = products.length;
</script>
Questions
Something else? Get in touch or read the docs.
Which site builders does this work with?
Any builder that lets you run custom JavaScript in the page, such as embed or custom code blocks. If a tool calls an API from its own servers rather than from the browser, CORS does not apply to that call and you may not need Proxify for it.
Do I need to write or host a backend?
No. Proxify is the server side of the request. You only change the URL your embed fetches.
Can I use an API that needs a secret token?
Yes. Store the token as a secret bound to the API’s host, then send X-Proxify-Upstream-Authorization: Bearer {{secret.NAME}} from your embed. Proxify swaps in the real token on the server.
My preview domain is different from my live domain.
Add both to the key's allowed origins, or use a test key while you build and switch to a live key before you publish.