Username and password: getting the proxy URL right
Updated 2 min read
Short version: every proxy comes with a username and password, on the Connection card of that proxy in your dashboard. Paste them exactly as shown. Most "wrong password" errors are really a broken proxy URL.
Where they are
Open Proxies, pick the line, click the proxy. The Connection card shows the Username and Password next to the host and port. Formatted gives you the whole line ready to paste.
They're generated for you, so you can't pick your own. Always copy them from the proxy you're connecting to.
The proxy URL
For HTTP proxies, put the credentials in the URL and your tool sends them in a Proxy-Authorization header:
curl -sS --proxy "http://USERNAME:PASSWORD@HOST:PORT" https://api.ipify.org; echo
Awkward characters
If a password contains @, :, /, # or %, the URL breaks, because your tool can't tell where the password stops. Two fixes:
-
Percent-encode it.
@becomes%40,:becomes%3A. To get the encoded version:python3 -c "import urllib.parse as u; print(u.quote('p@ss:word', safe=''))"That prints
p%40ss%3Aword. -
Keep the credentials out of the URL entirely:
curl -sS --proxy "http://HOST:PORT" --proxy-user 'USERNAME:PASSWORD' https://api.ipify.org; echo
SOCKS5
SOCKS5 carries the username and password in its own handshake, not in a header. With curl, use socks5h:// so the proxy looks up the site's hostname, not your machine:
curl -sS --proxy "socks5h://HOST:PORT" --proxy-user 'USERNAME:PASSWORD' https://api.ipify.org; echo
Use the port your dashboard lists for the protocol your proxy speaks. More in HTTP or SOCKS5?.
New password
Think a password leaked? If your proxy offers it, click Generate a new password on its Connection card. The username stays the same; anything still using the old password stops connecting straight away, so update your tools.
Still getting a 407?
- Copy-paste can bring a trailing space or line break with it. Delete it.
.envfiles are the usual culprit. - Browsers and desktop apps remember proxy logins. Changed the password? Clear the saved one.
On an IP allowlist? Then the proxy doesn't use a username and password at all. See IP allowlist: skip the username and password.
The full walkthrough is in Got a 407 or a 403? Here's what they mean. Still stuck? Email support@proxymonkey.io with your curl -v output, password removed.