---
title: Proxy Session Replay requests
description: Route browser replay ingestion and remote configuration requests through your own server.
product: session-replay
lang: en
token_estimate: 1022
---
# Proxy Session Replay requests

> For AI agents: a documentation index is available at [/docs/llms.txt](/docs/llms.txt). Append `.md` to any page URL for markdown, or send `Accept: text/markdown`.

Proxy browser Session Replay requests when you need SDK network traffic to pass through your own domain before reaching Amplitude. You can proxy requests independently of [hosting the browser script](https://amplitude.com/docs/session-replay/self-host-browser-script). Mobile Session Replay plugins don't support custom proxy URLs.

## Proxy API calls

Route SDK network requests through your own server so they don't go directly to `amplitude.com` endpoints. Your proxy server receives the request, forwards it to Amplitude's default endpoint, and returns Amplitude's response unchanged.

### How the proxy works

A minimal proxy implementation should:

1. Accept requests from the SDK at your custom URL.
2. Forward the full request body and all headers (except `Host`) to the corresponding Amplitude endpoint.
3. Return Amplitude's response to the SDK unchanged, including the status code, headers, and body.

Your proxy should be transparent. Don't strip, modify, or buffer the request or response payload. The SDK handles retries, so your proxy doesn't need to.

> **Tip:** Keep your API key server-side
>
> If you need to inject an `Authorization` header for a downstream service, inject the header in your proxy rather than hardcoding the API key in client-side code. Injecting the header server-side keeps credentials out of the browser.

### Optional Analytics SDK proxy

Analytics SDKs use separate ingestion and remote configuration endpoints. If your implementation also captures Analytics events, go to [Proxy Analytics SDK requests](https://amplitude.com/docs/sdks/analytics/proxy-requests).

### Session Replay: Browser (Plugin and Standalone SDK)

Session Replay sends captured data and fetches remote configuration through separate endpoints. Forward each request to the corresponding [API endpoint for your region](https://amplitude.com/docs/sdks/session-replay/session-replay-plugin#api-endpoints).

| Config option | Purpose |
| --- | --- |
| `trackServerUrl` | Point replay uploads to your proxy. |
| `configServerUrl` | Point remote configuration requests to your proxy. |

Session Replay Plugin:

```js
sessionReplayPlugin({
  trackServerUrl: 'https://replay.yourdomain.com/sessions/v2/track',
  configServerUrl: 'https://replay.yourdomain.com/config'
});
```

Session Replay Standalone SDK:

```js
sessionReplay.init('API_KEY', {
  trackServerUrl: 'https://replay.yourdomain.com/sessions/v2/track',
  configServerUrl: 'https://replay.yourdomain.com/config'
});
```

### Session Replay: Mobile (Android, iOS, React Native)

The mobile Session Replay plugins don't support custom proxy URLs. The only routing option is `serverZone`, which switches between Amplitude's US and EU data centers. Data still flows directly to Amplitude's servers and doesn't pass through your own infrastructure.

```kotlin
// Android — set on the Amplitude SDK configuration
serverZone = ServerZone.EU
```

```swift
// iOS — set on the Amplitude SDK configuration
serverZone: .EU
```

## Content Security Policy (CSP)

If your app sets a Content Security Policy, update it when switching to self-hosted files and proxied endpoints.

| Directive | Default (Amplitude CDN) | With self-hosting |
| --- | --- | --- |
| `script-src` | `https://cdn.amplitude.com` | Your own file-serving domain |
| `connect-src` | `https://api-sr.amplitude.com` (US) or `https://api-sr.eu.amplitude.com` (EU) | Your proxy domain(s) |
| `worker-src` | `blob:` | Keep `blob:`, required by the Session Replay web worker |

Example CSP (fully self-hosted):

```text
Content-Security-Policy: script-src 'self' https://assets.yourdomain.com; connect-src 'self' https://analytics.yourdomain.com https://replay.yourdomain.com; worker-src 'self' blob:;
```

Because your proxy handles routing to Amplitude's US or EU endpoints, the CSP only needs to reference your own domain. The same policy works for both regions.

