Can I call the API directly from my frontend? (CORS errors)
Last updated: September 17, 2026
No — and the CORS error you're hitting is protecting you from something worse.
Calling Baseten from browser JavaScript means shipping your API key to every visitor: anyone can open dev tools, copy the key, and run up your bill. Baseten endpoints don't return CORS headers, so browsers block these calls — treat that as guardrail, not obstacle.
The right architecture is a thin backend proxy:
Your frontend calls your own backend endpoint (a serverless function on Vercel, Netlify, Cloudflare Workers, or a route in your existing API).
That backend holds the Baseten API key as a server-side environment variable and forwards the request to Baseten.
The response streams back through it to your user.
This adds a few lines of code and gives you a place to add your own auth, rate limiting, and logging — which you'll want anyway before real users touch it.
If you've already exposed a key in frontend code, even briefly: revoke it now and issue a fresh one — see How do I report a leaked or compromised API key? in the Security collection.