Skip to content
Glossary

Proxy authentication

How a proxy verifies who you are, and the meaning of the 407 status code defined in RFC 9110.

Proxy authentication is the mechanism by which a proxy confirms you are entitled to use it. Two approaches dominate: credentials in the request, or IP whitelisting.

#Credential-based

The client sends a Proxy-Authorization header. Most tooling accepts credentials inline:

curl -x http://user:[email protected]:8000 https://api.example.com

Many providers overload the username field to carry routing parameters — country, session identifier, or protocol preference — separated by hyphens or colons. The syntax is provider-specific.

#The 407 status code

A proxy that requires authentication and does not receive valid credentials answers 407 Proxy Authentication Required, accompanied by a Proxy-Authenticate header describing the scheme.

The distinction that costs people time: 407 comes from the proxy, 401 comes from the destination. A 407 means your proxy credentials are wrong. A 401 means you reached the target and its own authentication rejected you. Treating them as the same error sends you debugging the wrong system.

#Reference

407 is specified in RFC 9110, section 15.5.8. The wider framework is described in RFC 7235.

#The two models compared

Credentials Address allow-list
Travels with the request Yes No
Works from any network Yes No, only from listed addresses
Survives a changing home address Yes No
Risk if leaked Anyone can use the account Attacker must also hold the address
Common failure 407 on every request Silent refusal after an address change

#Why credentials carry the configuration

Most residential providers encode more than identity in the username. Country, city, session identifier and rotation behaviour are frequently appended to it, because the gateway address stays fixed and the credential is the only field the client can vary per request.

This has a security consequence worth stating plainly: the username string is part of your configuration, so it ends up in code, in logs and in shell history. Keep the password out of URLs, and never log the full credential.

#Distinguishing 407 from 401

A 407 comes from the proxy and carries Proxy-Authenticate. A 401 comes from the destination and carries WWW-Authenticate. Confusing them sends you to debug the wrong system. See the status-code guide.

Frequently asked questions

What is the difference between 401 and 407?
The party asking. A 407 comes from the proxy and uses the Proxy-Authenticate and Proxy-Authorization headers. A 401 comes from the destination and uses WWW-Authenticate and Authorization. A 407 means the destination was never reached.
Why does my provider put a country code in the username?
Because the gateway hostname is fixed, so the credential is the only field that varies per request. Providers use it to carry country, city, session identity and rotation settings alongside the account name.
Should I put the password in the proxy URL?
Avoid it. A URL containing a password reaches shell history, process listings and logs. Pass credentials through a separate option where the client offers one, such as the -U flag in curl.

Sources

  1. RFC 9110: HTTP Semantics, Proxy-Authenticate and status 407

Related terms