PricingCompare CORS proxies
cors.dev vs allOrigins
allOrigins is free, needs no API key and wraps responses in JSON with a contents string. cors.dev returns the API response directly, also without an API key for public GET and HEAD requests, and publishes its limits.
Official pages checked .
allOrigins public API
Free
- Requests
- No published limits or pricing
- Endpoints
- /get?url= returns a JSON wrapper with a contents string; /raw?url= returns the body
- Caching
- Public cache headers; max-age=300 seen on the live API, 60 minutes default in the open-source app
- Methods & headers
- Your method is passed on; your request headers and body are not
- API key
- None; no account
- Availability
- Intermittent when checked: 2 of 8 calls returned 200, the rest Cloudflare 500, 520 and 522
- Self-hosting
- Open source; npm start listens on port 1458
cors.dev Pro
$5 / month
Plus tax where applicable.
- Requests
- 500,000 per monthly billing period
- Throughput
- 600 requests per minute and 10 concurrent requests per account; shared service limits also apply
- Targets
- Public HTTPS hostnames on port 443
- Size & time
- 1 MiB request body, 6 MiB response, 10 seconds
- Methods
- GET, HEAD, POST, PUT, PATCH and DELETE
- Headers
- Custom headers and explicit Authorization; no browser cookies or secret vault
- Caching
- Opt-in GET caching, 1 to 300 seconds. Eligible public responses only; cache hits count.
Check managed availability in your account. Free access is available now.
Create accountMigrate from allOrigins: swap the host for /raw, drop the wrapper for /get
allOrigins /raw?url= calls work on cors.dev with a host swap: replace api.allorigins.win with proxy.cors.dev and keep the ?url= parameter, plain or percent-encoded. /get?url= has no equivalent, because cors.dev returns the API response itself: switch to /raw?url= or the path form and drop the JSON.parse(contents) step. The charset and callback options are not supported; a parameter placed before url= is rejected with HTTP 400, and anything after a percent-encoded target is ignored.
// Before: allOrigins wraps the body in a JSON string
const target = encodeURIComponent('https://api.example.com/path');
const wrapped = await fetch(`https://api.allorigins.win/get?url=${target}`);
const { contents } = await wrapped.json();
const before = JSON.parse(contents);
// After: cors.dev returns the API response itself; /raw?url= only changes the host
const response = await fetch(`https://proxy.cors.dev/raw?url=${target}`);
const after = await response.json();
// Or skip the encoding and put the target URL in the path
const direct = await fetch('https://proxy.cors.dev/https://api.example.com/path');Choose for the requests you actually send.
allOrigins fetches any page, not only APIs, offers JSONP through callback and charset re-encoding, can be self-hosted in minutes, and costs nothing. Trade-offs: no published limits or pricing, public caching you cannot control on the hosted API (5 minutes seen live, 60 minutes by default in the open-source app), and request headers and bodies are not forwarded. On 28 September 2026 the API was intermittent: 2 of 8 calls returned 200 and the rest returned Cloudflare origin errors 500, 520 and 522. cors.dev publishes 600 requests per minute per IP anonymously, 1 MiB responses within 10 seconds, and Pro at $5 per month for 500,000 requests.
When to stay with allOrigins
Stay with allOrigins if you need JSONP through callback for very old browsers or charset re-encoding. Stay if you need images or other binary files on a free plan; cors.dev serves those only on trial and Pro. It handles responses above 1 MiB without a paid plan. You can also run the open-source app yourself on port 1458 where you control the cache. A demo tolerating cached data and occasional origin errors loses nothing by staying.
Try cors.dev with your own public HTTPS API if its request model fits your app. The managed trial includes 1,000 requests total over 7 days, without a card. For public GET and HEAD APIs, anonymous use needs no account.
Neither a request count nor a price establishes which service is faster or more reliable. Check your payloads, credentials and traffic pattern against the provider's current documentation.