Authenticating by IP allowlist
Updated 2 min read
With an IP allowlist, the proxy accepts connections from addresses you register and needs no username or password. It suits servers with a stable public address and tools that cannot send proxy credentials. While a proxy is set to the allowlist, its username and password stop working.
Step 1: find the address your traffic leaves from
Run this on the machine that will send the traffic, without a proxy:
curl -sS https://api.ipify.org; echo
Register the address it prints. A private address such as 10.x.x.x or 192.168.x.x will not work, and an address checked from your laptop is wrong for a cloud server.
Step 2: switch the proxy to the allowlist
- Open the proxy's page. On the Connection card, next to Authentication, select Change.
- Choose IP allowlist and enter the address in Allowed address. Entries must be single public IPv4 addresses: no ranges, no IPv6, no private addresses.
- Select Change authentication. The proxy now accepts only the addresses you listed.
To add or remove addresses later, open IP allowlist on the proxy's page, edit the list and select Save. The page shows how many of the allowed entries are in use. The list can be changed once every 30 minutes, so collect every address you need before saving. If a save is refused, try again after 30 minutes.
If there is no Change button next to Authentication, or the proxy's allowlist page says This plan authenticates by password, that proxy does not support allowlisting. Use Authenticating with username and password.
Step 3: verify
From the same machine, connect without credentials:
curl -sS -x "http://HOST:PORT" https://api.ipify.org; echo
Expected result: an address that is not your own. If the proxy refuses the connection, your traffic is leaving from an address that is not on the list. Repeat step 1 from that machine.
When the source address changes
| Situation | Effect | Action |
|---|---|---|
Home or office line with a dynamic address |
The address changes from time to time |
Update the list when access stops |
VPN |
Traffic leaves from the VPN's address |
Register the address the proxy actually sees |
Shared office network or NAT |
Every device behind it shares one address |
Everyone behind it can use the proxy |
Cloud server |
The address can change on restart |
Use a fixed address from your cloud provider |
To go back to credentials, use Change again and choose Username and password, then copy the Username and Password from the Connection card into every client that uses the proxy.