FAQ

Questions about the proxy, its rules, and its limits.

Need help with domain approval, request limits, or image transformation behavior? Send us a message and we’ll walk through it together.

General

Call the proxy endpoint with a source image URL in the url query parameter and any transform options you need, for example width, height, fit, output, and quality. The endpoint is served at /ctrlin.

Output can be JPEG, PNG, WebP, AVIF, GIF, or TIFF using the output parameter. If you do not set it, the app uses the default output behavior configured by the transform pipeline.

Source images are capped by the app’s configured source limit, and Free-mode domains are automatically kept at a shared 10 requests per minute. Paid domains may use a higher configured rate limit.

Billing

Free-mode domains automatically have their rate limit fixed at 10 requests per minute. Paid-mode domains keep whatever rate limit you set — it's never auto-corrected.

Each account can register up to 25 domains by default. Need more? Reach out about an Enterprise plan.

Yes, from your user panel. Switching to Paid stops the automatic 10 req/min correction; switching back to Free reapplies it.

An unfinished (pending) payment is automatically cleared after 24 hours. It's not held against you — just start a new payment whenever you're ready.

Security & privacy

Source images are fetched and transformed in memory, then cached for fast repeat delivery. The proxy does not keep a long-term image archive; it is optimized for fast, repeated access over the approved domain list.

Hit/traffic logs are kept for 30 days and activity history (domain and rate-limit changes) for 20 days, then automatically deleted. Your dashboard totals reflect that rolling window rather than all-time history.

Every request must carry a Referer or Origin header whose hostname is on your approved domain list. Requests from unlisted or disabled domains are rejected the same way, so attackers can't tell which reason applied.

Domain names are matched by string, not verified against DNS, so they're claimed first-come, first-served. We'd recommend adding your domain as soon as you plan to use it.

Technical

Source URLs are checked before fetching — private, loopback, and metadata addresses are blocked, and you can further restrict which source domains are fetchable at all.

Width, height, fit mode, gravity, device pixel ratio, quality, background color, blur, sharpen, gamma, and contrast — plus a fallback URL to redirect to if the source ever fails to load.

Still stuck?

Our support team typically replies within a few hours.

Contact support