Authenticating with username and password
Updated 2 min read
With username and password authentication, the client sends credentials on every connection to the proxy. It works from any network, which makes it the default for laptops, CI runners and serverless functions whose outbound address changes.
Step 1: copy the credentials
Open the proxy's page and copy the host, port, Username and Password from the Connection card. See Finding your host, port and credentials. Use them exactly as shown; do not reuse another provider's format.
Step 2: pass them to the client
For an HTTP or HTTPS proxy, the client sends the credentials in a Proxy-Authorization: Basic header. Most clients build that header from credentials embedded in the proxy URL:
curl -sS -x "http://USERNAME:PASSWORD@HOST:PORT" https://api.ipify.org
To keep the password out of the URL, pass it as a separate option:
curl -sS -x "http://HOST:PORT" --proxy-user "USERNAME:PASSWORD" https://api.ipify.org
For SOCKS5, the credentials travel in the SOCKS handshake instead of a header. Use the socks5h:// scheme with curl so that the proxy, not your machine, resolves the target host name.
Step 3: encode special characters
A password containing @, :, /, # or % breaks a proxy URL unless it is percent-encoded. In Python:
from urllib.parse import quote
proxy = f"http://USERNAME:{quote(PASSWORD, safe='')}@HOST:PORT"
Expected result
The command prints an address that is not your own. That address is the exit the target sees.
If it fails
- A
407means the proxy did not accept the credentials. Follow Diagnosing proxy status codes 407 and 403. - A copied password may carry a trailing space or line break. Paste it into a plain text editor to check.
- A browser or desktop tool may have saved an older password. Clear the saved entry after any credential change.
- Check Authentication on the proxy's Connection card. A proxy set to IP allowlist has no working username and password. See Authenticating by IP allowlist.
Replacing a password
If a password may have leaked, open the proxy's page and select Generate a new password. The old password stops working immediately, and every client fails until it has the new one. Usernames and passwords are generated; you cannot choose your own. If the button is not shown, write to support@proxyforge.io with the proxy ID.
Store the credentials in a secrets manager, not in source code. Never send the password to support.