● Edge delivery infrastructure

Fast, secure delivery at the global edge.

The Edge CDN API provides controlled access to globally distributed content delivery infrastructure. Requests are securely brokered through your application layer rather than exposed directly to clients.

!
Direct client access is not permitted The Edge CDN API is an internal service and must never be called directly from browsers, mobile applications, or other untrusted clients. Route requests through your authorized backend or API gateway.

Built for controlled edge delivery.

Use the API from trusted server-side infrastructure to manage or retrieve CDN resources while keeping credentials, origin configuration, and internal endpoints outside the public application surface.

↯

Edge-first performance

Deliver cacheable resources from infrastructure positioned close to end users around the world.

◈

Controlled access

Keep API credentials and privileged CDN operations behind your own trusted server-side boundary.

✓

Production ready

Designed for predictable integration with backend services, gateways, workers, and internal automation.

Keep the edge API behind your application.

The public client communicates only with your application. Your trusted backend then communicates with the Edge CDN API using server-side credentials.

Client

Browser, mobile app, or other public client.

›

Your backend / API gateway

Authentication, authorization, validation, rate limiting, logging, and credential management.

›

Edge CDN API

Internal service responsible for edge delivery operations.

Important: Do not embed Edge CDN API credentials in frontend JavaScript, mobile binaries, public repositories, or other client-side code. A browser should never need to know the internal API endpoint.

Server-side integration.

The following illustrates the intended integration pattern. Replace the endpoint and authentication details with the values supplied for your deployment.

POST /internal/edge
// Example request from your trusted backend

{
  "operation": "purge",
  "resource": "/assets/app.js"
}
Authentication
Server-side credentials only. Required
Client access
Direct browser or mobile requests are prohibited. Restricted
Transport
Use HTTPS for every request between trusted services. TLS
Validation
Validate and authorize incoming application requests before forwarding them to the Edge CDN API.

Security is part of the architecture.

The API is intentionally not designed as a public client-facing endpoint. Keeping it behind a trusted service boundary reduces credential exposure and provides a central place to enforce policy.

⌁

Credentials

Store secrets exclusively in server-side secret management or environment configuration. Never expose them to clients.

⊙

Authorization

Verify that each incoming application request is authorized before performing a privileged CDN operation.

≋

Observability

Centralize request logging, auditing, rate limiting, and operational monitoring at the backend boundary.

Do not proxy blindly. Your public endpoint should not simply forward arbitrary URLs, headers, or operations to the Edge CDN API. Validate inputs and expose only the operations your application actually requires.