集成于Web CRM的DeepL API遭CORS策略拦截,请求失败求助
DeepL API 跨域请求被拦截问题的原因与解决方案
核心原因
DeepL API(免费版及付费版)不支持直接从浏览器前端发起跨域请求,此前能正常运行应该是DeepL临时开放过CORS支持,新年后他们调整了服务策略,关闭了浏览器端的跨域权限。这是API服务商的常规安全措施——直接在前端暴露auth_key会导致密钥泄露,引发盗用额度等风险。
Postman能正常调用是因为它属于非浏览器环境的请求,不会触发浏览器的CORS校验机制;而浏览器会强制校验跨域请求的响应头,DeepL当前的响应中未返回Access-Control-Allow-Origin头,因此请求被拦截。
可行解决方案
- 后端代理请求:在你的CRM系统后端搭建代理接口,前端请求该代理接口,由后端代为调用DeepL API。这种方式既规避了CORS问题,又能将
auth_key安全存储在后端,避免密钥泄露。
示例(Node.js/Express 后端代理):
前端修改请求地址为后端代理接口:const express = require('express'); const axios = require('axios'); const app = express(); // 代理翻译请求 app.get('/api/proxy-deepl', async (req, res) => { const deeplAuthKey = '你的DeepL API密钥'; const { text, target_lang, preserve_formatting, split_sentences } = req.query; try { const deeplResponse = await axios.get('https://api-free.deepl.com/v2/translate', { params: { auth_key: deeplAuthKey, text, target_lang, preserve_formatting: preserve_formatting || 1, split_sentences: split_sentences || 0 } }); res.json(deeplResponse.data); } catch (error) { res.status(error.response?.status || 500).json({ error: error.response?.data?.message || '翻译请求失败' }); } }); app.listen(3000, () => console.log('代理服务启动'));var url = "/api/proxy-deepl?target_lang=DE&preserve_formatting=1&split_sentences=0&text=bonjour"; $.ajax({ url, type: 'GET', success: (translations) => { console.log(translations); } }); - 确认官方最新规则:查阅DeepL官方文档,确认是否新增了浏览器端的合法调用方式,但目前官方明确建议API密钥仅在服务器端使用,禁止前端直接暴露密钥。
内容的提问来源于stack exchange,提问作者Bertrand PETIT
相关产品推荐
相关产品推荐

