# API settings

The top-level `api` field controls how the "Try it" modal on OpenAPI-powered pages sends requests — separate from a navigation group's own `openapi: { src, path }` (which spec to use, and where it's mounted; see [API Reference (OpenAPI)](/docs/openapi/overview/)).

<Parameter name="proxy" type="boolean" default="true" />

```json
{
  "api": {
    "proxy": false
  }
}
```

## `api.proxy`

The "Try it" modal's Send button always calls your API directly from the reader's browser first. Many APIs don't send back `Access-Control-Allow-Origin` headers permitting an arbitrary docs site's origin, so the browser blocks that request. When `api.proxy` is `true` (the default), a blocked request is sent again through Writedocs' own CORS proxy, and the response line says it went through the proxy.

One exception: a `POST` with no JSON body, no auth and no custom headers can reach your API even when the browser blocks the response, so it isn't retried - that would risk running it twice.

Set `api.proxy` to `false` if you never want requests routed through a third party - requests your API blocks then fail with a CORS message.

A key a reader types into the playground is kept for the browser tab only (`sessionStorage`), and forgotten when the tab closes.