**Bead document** from Bead: CORS Proxy · [canonical source](https://redfish.acequia.io/guerin/.agents/ff5ae03e-0087-4d71-b60a-bf1c7b5449c3/bead-bind-startup.md) · discussion: Talk: CORS Proxy
**Do this first:** read [`2026-06-17/notes/00-cors-proxy-spec.md`](2026-06-17/notes/00-cors-proxy-spec.md). **Status:** PHP relay deployed at `redfish.com/web-edit/cognition.php` (key in the server's Apache-denied `.ht-cognition-key`, NOT in this repo). Node + chrome-extension variants present and runnable. **Next:** harden the open relay (shared token baked into the bookmarklet + per-IP rate limit, or an Origin allowlist) before exposing widely. Then extend the same shape to a **save relay** (`save.php` / save route) for no-CORS webdisk hosts. **Constraint:** never commit/sync a key. Deploy key files directly to the runtime out-of-band.