corsproxy.dev

dev.corsproxyv1.0.0Updated Oct 1, 2026

Call third-party APIs from agents without leaking secrets. SSRF blocked, per-key quotas.

VerifiedStreamable HTTPWeb executableDeveloper ToolsSecurity & Monitoring

Overview

AI-generated overview

Lets an assistant call third-party APIs through a proxy that keeps API keys out of the agent and blocks SSRF attempts.

What it does
A remote MCP endpoint that relays outbound HTTP requests to third-party APIs on the assistant's behalf. According to the description, it hides the caller's secrets from the agent and applies SSRF blocking plus per-key quotas. No tool list is published, so the exact request and response surface is not documented here.
When to use it
Worth considering when an assistant needs to reach external HTTP APIs but you do not want to hand it raw credentials, or when you want a shared quota and SSRF filtering layer in front of those calls.
Requirements
A remote streamable HTTP endpoint; no local package or runtime is needed. An API key for the service must be supplied in the X-API-Key header. Network access to the endpoint is required.
Before you install
The X-API-Key header carries a secret credential, so treat it as sensitive and scope it narrowly. Requests are relayed through a third party, meaning the target URLs and payloads pass through that service. The description mentions per-key quotas, so usage may be metered or limited.

Installation

In SourceWeft

  1. Open corsproxy.dev in the dashboard and add it to a workspace.
  2. Enable the server for the chats that should use its tools.

Web executable via Streamable HTTP. Remote servers run from the web runtime once configured in a workspace.

Other MCP clients

Add this to your client's mcpServers config.

{
  "mcpServers": {
    "mcp": {
      "type": "http",
      "url": "https://api.corsproxy.dev/mcp"
    }
  }
}

Tools

0
Tool metadata has not been indexed yet.

Version history

1
  1. v1.0.0LatestOct 1, 2026