Proxy authentication
How a proxy verifies who you are, and the meaning of the 407 status code defined in RFC 9110.
Proxy authentication is the mechanism by which a proxy confirms you are entitled to use it. Two approaches dominate: credentials in the request, or IP whitelisting.
#Credential-based
The client sends a Proxy-Authorization header. Most tooling accepts credentials inline:
curl -x http://user:[email protected]:8000 https://api.example.com
Many providers overload the username field to carry routing parameters — country, session identifier, or protocol preference — separated by hyphens or colons. The syntax is provider-specific.
#The 407 status code
A proxy that requires authentication and does not receive valid credentials answers 407 Proxy Authentication Required, accompanied by a Proxy-Authenticate header describing the scheme.
The distinction that costs people time: 407 comes from the proxy, 401 comes from the destination. A 407 means your proxy credentials are wrong. A 401 means you reached the target and its own authentication rejected you. Treating them as the same error sends you debugging the wrong system.
#Reference
407 is specified in RFC 9110, section 15.5.8. The wider framework is described in RFC 7235.
#The two models compared
| Credentials | Address allow-list | |
|---|---|---|
| Travels with the request | Yes | No |
| Works from any network | Yes | No, only from listed addresses |
| Survives a changing home address | Yes | No |
| Risk if leaked | Anyone can use the account | Attacker must also hold the address |
| Common failure | 407 on every request | Silent refusal after an address change |
#Why credentials carry the configuration
Most residential providers encode more than identity in the username. Country, city, session identifier and rotation behaviour are frequently appended to it, because the gateway address stays fixed and the credential is the only field the client can vary per request.
This has a security consequence worth stating plainly: the username string is part of your configuration, so it ends up in code, in logs and in shell history. Keep the password out of URLs, and never log the full credential.
#Distinguishing 407 from 401
A 407 comes from the proxy and carries Proxy-Authenticate. A 401 comes from the destination and carries WWW-Authenticate. Confusing them sends you to debug the wrong system. See the status-code guide.