corsproxy.dev
dev.corsproxyv1.0.0Updated Oct 1, 2026
Call third-party APIs from agents without leaking secrets. SSRF blocked, per-key quotas.
Overview
AI-generated overview
Lets an assistant call third-party APIs through a proxy that keeps API keys out of the agent and blocks SSRF attempts.
- What it does
- A remote MCP endpoint that relays outbound HTTP requests to third-party APIs on the assistant's behalf. According to the description, it hides the caller's secrets from the agent and applies SSRF blocking plus per-key quotas. No tool list is published, so the exact request and response surface is not documented here.
- When to use it
- Worth considering when an assistant needs to reach external HTTP APIs but you do not want to hand it raw credentials, or when you want a shared quota and SSRF filtering layer in front of those calls.
- Requirements
- A remote streamable HTTP endpoint; no local package or runtime is needed. An API key for the service must be supplied in the X-API-Key header. Network access to the endpoint is required.
Before you install
The X-API-Key header carries a secret credential, so treat it as sensitive and scope it narrowly. Requests are relayed through a third party, meaning the target URLs and payloads pass through that service. The description mentions per-key quotas, so usage may be metered or limited.
Installation
In SourceWeft
- Open corsproxy.dev in the dashboard and add it to a workspace.
- Enable the server for the chats that should use its tools.
Web executable via Streamable HTTP. Remote servers run from the web runtime once configured in a workspace.
Other MCP clients
Add this to your client's mcpServers config.
{
"mcpServers": {
"mcp": {
"type": "http",
"url": "https://api.corsproxy.dev/mcp"
}
}
}Tools
0Tool metadata has not been indexed yet.
Version history
1- v1.0.0LatestOct 1, 2026

