DocsAUTO

Install Auto

Auto wraps browser fetch and standard asynchronous XMLHttpRequest calls. Keep the original API URLs in your codebase; install Auto before anything captures those browser transports.

Add the classic script

index.html — install before your application
<script src="https://cors.dev/auto.js"></script>
<script src="/app.js"></script>

Place both tags in this order on an HTTP(S)-served page. Do not add async: your app could start before Auto is installed. Compatible public GET and HEAD requests require no key.

When a native request succeeds, it stays native by default, readable HTTP errors included. Same-origin calls are left alone. If an eligible read rejects before returning a response, Auto can try the proxy once.

Bootstrap with browser ESM

bootstrap.js — browser ESM
import { installAuto } from 'https://cors.dev/auto.mjs';

async function start() {
  installAuto();
  await import('./app.js');
}

start().catch((error) => {
  console.error('Could not start the application:', error);
});

index.html — load your bootstrap
<script type="module" src="/bootstrap.js"></script>

Importing auto.mjs does not install Auto: call installAuto(). Dynamically importing your app afterward ensures its dependencies run after installation. A static import "./app.js" beside the install call does not guarantee that order.

Vendor the module for bundlers

If your bundler does not support HTTPS imports, download a pinned auto.mjs into your application as vendor/auto.mjs and import it locally. There is no npm package to install. Both the classic script and ESM module are self-contained.

bootstrap.js — a downloaded ESM artifact
import { installAuto } from './vendor/auto.mjs';

async function start() {
  installAuto();
  await import('./app.js');
}

start().catch((error) => {
  console.error('Could not start the application:', error);
});

TypeScript projects need a declaration for the vendored module or JavaScript module checking configured in their project. Keep the dynamic application import. Check deployment for pinning and CSP.

Check where requests went

In DevTools Network, native calls point directly to the API host; proxied requests head to proxy.cors.dev with the API URL in the path. A CORS diagnostic from the initial native attempt can linger in the console even when the proxy attempt succeeds. Inspect the final response and body rather than stopping at the console message.

A failed native read may already have reached the API, so an eligible GET or HEAD can execute twice. Use Auto for read-only endpoints; use the native escape for one-use URLs or GETs with side effects.

For managed requests, configure a Connection first. Cookies, unsupported uploads, and specialized Fetch options stay native, even with proxy-only mode. Auto does not intercept WebSocket or EventSource.