{"success":true,"data":{"version":"0.1.0","title":"corsproxy.dev API","description":"Managed CORS proxy API. API keys work only on the endpoints listed here; account management happens in the dashboard.","endpoints":{"health":{"method":"GET","path":"/v1/health","description":"Health check endpoint"},"mcp":{"method":"POST","path":"/mcp","description":"Remote MCP server (Streamable HTTP, JSON-RPC 2.0) with tools fetch_url, check_quota, explain_error","auth":"API Key (X-API-Key header) plus an Origin allowed on the key","notes":"Setup: https://corsproxy.dev/docs/#mcp"},"proxy":{"get":{"method":"GET","path":"/proxy?url=<target_url>&key=<api_key>","description":"Proxy a GET request with CORS headers","auth":"API Key (X-API-Key header or key query param)","notes":"Drop-in public proxy path. If you are migrating from another hosted CORS proxy, replace the base proxy URL and keep the target URL in the url query parameter. Browser integrations can pass the API key in the key query param; server-side callers can use the X-API-Key header. API keys can also carry managed upstream header rules for specific target hosts and path prefixes, so browser code does not need to expose provider credentials. Also available at /v1/proxy. Blocks private, loopback, link-local (incl. cloud metadata), CGNAT and private IPv6 targets (BLOCKED_HOST)."},"post":{"method":"POST","path":"/proxy","description":"Proxy a POST/PUT/PATCH/DELETE request","auth":"API Key (X-API-Key header or key query param)","body":{"url":"string (target URL)"},"notes":"Forwards any HTTP method. Public compatibility path; /v1/proxy remains supported. Accepts the API key from the X-API-Key header or key query param. Managed upstream headers can be injected for matching target hosts/path prefixes. CORS headers injected in response. Rate limited. Optional: ttl (Pro edge caching), repeatable reqHeaders/resHeaders. Rejections return { success: false, code, error } with a stable reason key; full list at https://corsproxy.dev/docs/#errors."}}}}}