← All solutions & integration guides

No-code integration

Connect APIs from your no-code browser embeds

Use CORSPROXY when JavaScript in your published page calls an API that does not allow your website origin. First check whether your platform sends the request from the browser or its own server.

Updated

Start with the request that fails

Open your browser’s Network panel and find the API request. A missing CORS response header is a browser problem. An upstream 401, 403, or 429 can mean missing credentials, denied access, or a provider limit; adding a proxy does not automatically fix those errors.

Webflow and Framer custom code

Use the snippet below in a custom JavaScript embed, replace the API URL with your public endpoint, and add an element with data-api-result where the response should appear. Register your published site’s domain in the dashboard before testing it.

const params = new URLSearchParams({
  key: 'YOUR_API_KEY',
  url: 'https://api.example.com/public/data',
});
const response = await fetch('https://corsproxy.io/?' + params);
if (!response.ok) {
  throw new Error('HTTP ' + response.status + ': ' + await response.text());
}
const data = await response.json();
const output = document.querySelector('[data-api-result]');
if (output) output.textContent = JSON.stringify(data, null, 2);

Bubble: browser actions versus the API Connector

Bubble’s API Connector normally sends requests through Bubble’s server. Browser CORS does not apply to that server request. CORSPROXY is useful for browser-side JavaScript actions or calls explicitly configured to run in the browser. Check the request path before adding another proxy.

Read Bubble’s API Connector guidance. Keep private provider credentials in the platform’s private server-side settings.

Retool: check where the query runs

A direct fetch() in browser JavaScript may need CORS headers. A query executed by a backend resource or server workflow has a different request path. Use your platform’s backend integration when the provider requires a secret token.

Feed widgets and remote images

For news or podcast widgets, read the RSS & Feeds guide. For external product photos, use image delivery or transformation.

Test the published domain

Preview and published pages can have different origins. Register the site making the request, use your own CORSPROXY key, and test the published page. On shared hosting, check the registered domain scope shown by the dashboard.

Follow the deployment checklist or diagnose a failed request.