Override Forbidden Request Headers
Set headers like Origin, Referer, and User-Agent that browsers normally block. Corsfix overrides them server-side so your requests reach the API exactly how you need.
GET /data HTTP/1.1 Host: remote-api.com Origin: https://yourdomain.comAccept: application/jsonReferer: https://yourdomain.com/ User-Agent: Mozilla/5.0Referer: https://remote-api.com/ User-Agent: GoogleBot/1.0
Set any request header from your frontend
Pass the headers you need in the headers option. Corsfix applies them server-side, bypassing browser restrictions. Find more usage details in our header override documentation.
// Set Origin, Referer and User-Agentcorsfix.fetch("https://api.example.com/data", {corsfix: {headers: {Origin: "https://example.com",Referer: "https://example.com/","User-Agent": "MyApp/1.0",},},});// Corsfix applies these server-side// The target API receives exactly what you specified
Honestly, working with Corsfix has been incredible, the level of support is top-notch, and using Corsfix has improved the entire user experience for our Figma plugin.

Lead Product Designer at Taco Bell
I've loved the way you're really trying to satisfy users' requests to make Corsfix an outstanding product. This is the aptitude I really like to see around me and my team.

Co-founder and CTO at tuOtempO
I've tried a couple more proxy services but they didn't work as I was expecting, or at all. With that said I was quite surprised at how easy it was to use Corsfix and how well it's documented.

Web Developer
Frequently Asked Questions
What are forbidden request headers?
Origin, Referer, User-Agent, Host, and any header starting with Sec- or Proxy-.Why can't I set the Origin or Referer header in JavaScript?
How do I override forbidden headers with Corsfix?
headers option, for example corsfix.fetch(url, { corsfix: { headers: { Origin: "https://example.com" } } }). If you call the proxy URL directly, send them as a JSON-stringified object in the x-corsfix-headers header instead. Corsfix will apply those headers server-side before forwarding your request to the target API. For example, you can set Origin, Referer, or User-Agent to any value you need.What is the full list of forbidden header names?
Accept-Charset, Accept-Encoding, Access-Control-Request-Headers, Access-Control-Request-Method, Connection, Content-Length, Cookie, Date, DNT, Expect, Host, Keep-Alive, Origin, Referer, TE, Trailer, Transfer-Encoding, Upgrade, Via, User-Agent, and any header starting with Sec- or Proxy-. See the MDN Web Docs for the complete reference.When would I need to override request headers?
Can I override multiple headers at once?
headers option takes an object, so you can include as many headers as you need in a single request. For example, you can override both Origin and Referer at the same time.Is overriding request headers safe?
Stop fighting browser restrictions
Override any request header with Corsfix. Free to get started.





