GuidesDECIDE

Choosing between a CORS proxy and your own backend

Browsers block cross-origin requests when the target server omits the required access control headers. Developers facing this block choose between updating the target server, running custom relay code, or routing through an existing service. Each approach distributes maintenance, cost, and security responsibilities differently.

Add CORS headers to your own API

When developers attempt to bypass CORS restrictions on their own services, configuring the server to return the Access-Control-Allow-Origin header is the direct solution. This eliminates intermediate network hops and keeps authentication tokens private between the browser and your API. Placing an intermediary in front of an API you own adds an unnecessary network dependency that can read every payload.

Route requests through existing infrastructure

Most applications already deploy a backend component such as an application server, serverless function, or edge worker. You can add a dedicated endpoint to that existing server to fetch data from the external service and deliver it to your frontend. This route allows you to keep API keys and credentials secure on the server while caching responses under your domain.

Run a dedicated self-hosted relay

Deploying a standalone relay such as cors-anywhere creates a dedicated proxy under your control. You determine the allowed request origins and rate limits for that specific host. The code footprint is small, but your team assumes permanent responsibility for hosting costs, uptime monitoring, security patches, and traffic abuse.

Use a managed proxy for public endpoints

A managed cors proxy removes server operations when reading public third-party endpoints. Routed traffic passes through infrastructure operated by a third party, meaning the operator can observe every request and response. Use this pattern exclusively for unauthenticated, public data where you accept the operator's availability and bandwidth limits.

The cors.dev free tier: GET and HEAD requests to any public HTTPS host, JSON, XML, HTML, CSV and other text responses up to 1 MiB, a 10-second deadline, automatic redirect following, and a shared request pool with fair-use rate limits. Managed access adds POST/PUT/PATCH/DELETE on public HTTPS hostnames enabled on your Connection, explicit Authorization and custom API headers, 1 MiB request bodies, and 6 MiB responses within 10 seconds. The trial includes 1,000 requests total over 7 days; Pro costs $5/month for 500,000 requests per monthly billing period. Browser cookies are not forwarded, and private frontend credentials belong on your own backend.

Comparison of CORS resolution options
OptionWho owns itSecrets safeOngoing maintenance
Fix own APIYouYesLow (code change only)
Server you already haveYouYesLow (existing infra)
Narrow self-hosted relayYouYesHigh (dedicated server)
Anonymous free tier (cors.dev)Third partyNo (public data only)Zero
Remove the integrationNobodyYesZero

Developers testing prototype features can verify upstream responses directly in the playground before deployment. When your application moves to production, review the pricing page to verify tier limits or inspect the documentation for supported upstreams.

Remove the dependency entirely

Some third-party integrations provide minor interface details that do not justify ongoing operational overhead. If an external API refuses to add CORS headers and you lack backend infrastructure to proxy it, dropping the feature avoids long-term technical debt. Secondary widgets that fail silently or break on unexpected upstream outages degrade user trust.

Good questions.

Is a managed CORS proxy safe to use?

A managed proxy is safe for public data that requires no authentication headers or cookies. Because the proxy operator can inspect all traffic passing through their systems, sensitive credentials and private customer records must never pass through a public proxy.

What does a self-hosted relay actually cost to run?

Running your own relay requires paying for compute hours, bandwidth, and maintenance time. An open relay like cors-anywhere on public infrastructure attracts scrapers and automated attacks unless you enforce strict origin allowlists and rate limits.

Can I start with a proxy and move to my own backend later?

Yes. Frontend code using a proxy merely prefixes the target URL with the proxy origin. When you build a backend route, replace that prefix with your application's own API path.