Self-hosted proxy
If you run your own server or edge functions, you can forward Foresite's two requests through your own domain:
GET /s/YOUR_SITE_ID.js→https://t.foresite.dev/s/YOUR_SITE_ID.jsPOST /e→https://t.foresite.dev/e
On both routes, your proxy must send:
X-Foresite-Proxy-Secret: your site's proxy secret, from Settings → Install. Without it, Foresite ignores the two headers below, so nobody can fake visitors' addresses or redirect your events.X-Forwarded-For: the visitor's IP address, so countries and unique visitors are counted correctly. Foresite uses it only in memory and never stores it.X-Forwarded-Host: your own domain, so the script sends events back through your proxy.
Don't forward cookies. Foresite never reads them.
nginx
location ~ ^/(s/YOUR_SITE_ID\.js|e)$ {
proxy_pass https://t.foresite.dev;
proxy_ssl_server_name on;
proxy_set_header Host t.foresite.dev;
proxy_set_header X-Forwarded-Host $host;
proxy_set_header X-Forwarded-For $remote_addr;
proxy_set_header X-Foresite-Proxy-Secret "YOUR_PROXY_SECRET";
proxy_set_header Cookie "";
}
Cloudflare Workers
export default {
async fetch(request) {
const url = new URL(request.url)
if (url.pathname !== '/e' && !url.pathname.startsWith('/s/')) return fetch(request)
const headers = new Headers({
'Content-Type': request.headers.get('Content-Type') || 'text/plain',
'User-Agent': request.headers.get('User-Agent') || '',
'X-Forwarded-For': request.headers.get('CF-Connecting-IP') || '',
'X-Forwarded-Host': url.host,
'X-Foresite-Proxy-Secret': 'YOUR_PROXY_SECRET',
})
return fetch('https://t.foresite.dev' + url.pathname, {
method: request.method,
headers,
body: request.method === 'POST' ? await request.text() : undefined,
})
},
}
Your Foresite line then loads the script from your own domain, e.g. <script defer src="https://www.example.com/s/YOUR_SITE_ID.js"></script>, and events follow the same route.