could also just do the request in javascript instead of needing a (presumably hosted) sandbox
I also think it's weird to be so willing to let people run arbitrary CURL commands from your platform, without any billing or account verification. It feels ripe for abuse.
[0]: https://developer.mozilla.org/en-US/docs/Web/HTTP/Guides/COR...
CORS was a blocker for client side requests, I have a separate branch where this is integrated, maybe will add it alongside server side execution to let the person creating the curl decide whether they can execute on browser or server side.