407 Proxy Authentication Required: How to Fix It in C# and .NET

Developer guide · Last reviewed 27 September 2026 · 10 min read

A 407 Proxy Authentication Required error means your request reached the proxy, but the proxy didn’t get valid credentials, so it refused to forward it. In C# it usually appears as “The remote server returned an error: (407) Proxy Authentication Required”. This guide explains what the proxy is asking for, shows the working fix for .NET HttpClient and the older HttpWebRequest, gives the equivalent fixes for curl and Python, and lists the real-world causes we see most with residential proxies.

The short version

Give the proxy its username and password on the proxy object, not on the request: in C#, create a WebProxy with Credentials = new NetworkCredential(user, pass) and pass it to HttpClientHandler.Proxy. If you already do that and still get 407, the credentials are wrong or out of date. With ProxyEmpire, the username changes when you change targeting, so copy it again from the dashboard.

What 407 Proxy Authentication Required Means

The proxy wants credentials before it forwards anything

HTTP status code 407 is the proxy’s version of 401. MDN describes it as a request that didn’t succeed because it lacks valid authentication credentials for the proxy server between the client and the target. The proxy sends a Proxy-Authenticate header saying how it expects you to log in, and the client has to repeat the request with a Proxy-Authorization header carrying the credentials.

What happens on the wire
client  ->  proxy     GET / CONNECT (no credentials)
proxy   ->  client    HTTP/1.1 407 Proxy Authentication Required
                      Proxy-Authenticate: Basic realm="..."
client  ->  proxy     same request + Proxy-Authorization: Basic <base64 user:pass>
proxy   ->  target    request forwarded, response comes back

Two things follow from that. First, the error comes from the proxy, not the website you’re trying to reach, so changing anything about the target URL won’t fix it. Second, the fix is always about the proxy’s credentials: whether your client sends them, whether it sends them to the proxy rather than the target, and whether they’re correct.

Common Causes of a 407 Error

In order of how often we see them
CauseWhat to check
Credentials never sent to the proxyThe username and password are set on the request or the client, not on the proxy object. In .NET they belong on WebProxy.Credentials.
Out-of-date usernameWith ProxyEmpire, the username encodes your targeting and session. Change the country or session and the username changes too.
Typo or hidden spaceA trailing space or line break copied with the password. Copy both values again from the Proxy Manager.
Special characters in a URLIf credentials are written into a proxy URL, characters such as @, : and / must be URL-encoded.
The system proxy is used insteadThe client picked up a proxy from Windows settings or environment variables, which doesn’t have your credentials.
Client refuses Basic authSome runtimes disable Basic authentication for HTTPS tunnels by default. Java is the best-known example.

Fix 407 Proxy Authentication Required in C# HttpClient

Credentials on the WebProxy, proxy on the handler

In modern .NET, HttpClient gets its proxy from its handler. Microsoft’s documentation for HttpClientHandler.Proxy explains that when you set this property, it overrides any proxy from the machine or application configuration, so your code controls exactly which proxy and credentials are used.

C# — HttpClient through an authenticated proxy
using System.Net;

var proxy = new WebProxy("http://v2.proxyempire.io:5000")
{
    Credentials = new NetworkCredential(
        Environment.GetEnvironmentVariable("PROXY_USER"),
        Environment.GetEnvironmentVariable("PROXY_PASS"))
};

var handler = new HttpClientHandler
{
    Proxy = proxy,
    UseProxy = true
};

using var client = new HttpClient(handler);
string ip = await client.GetStringAsync("https://api.ipify.org");
Console.WriteLine(ip);   // should print the proxy's IP, not yours

Notes on getting it right:

  • Put the credentials on WebProxy.Credentials. Setting HttpClientHandler.Credentials instead sends them to the target site, not the proxy, and you keep getting 407.
  • Create the handler once and reuse the client. A new HttpClient per request wastes connections. If you need different proxy sessions, keep one client per session.
  • HTTPS works through the same proxy. The client opens a tunnel to the target with a CONNECT request and authenticates to the proxy for it. The traffic to the site stays encrypted end to end.
  • SocketsHttpHandler works the same way. It also has a Proxy property that takes the same WebProxy object.

Fix “The remote server returned an error: (407)” in HttpWebRequest

Older .NET Framework code

The exact message “The remote server returned an error: (407) Proxy Authentication Required” comes from a WebException, which is what HttpWebRequest throws. It’s common in older .NET Framework applications. The fix is the same idea: set a WebProxy with credentials on the request.

C# — HttpWebRequest (.NET Framework) with proxy credentials
using System.IO;
using System.Net;

var request = (HttpWebRequest)WebRequest.Create("https://api.ipify.org");
request.Proxy = new WebProxy("http://v2.proxyempire.io:5000")
{
    Credentials = new NetworkCredential("USERNAME", "PASSWORD")
};

using (var response = (HttpWebResponse)request.GetResponse())
using (var reader = new StreamReader(response.GetResponseStream()))
{
    Console.WriteLine(reader.ReadToEnd());
}

WebRequest and HttpWebRequest are marked obsolete in modern .NET, so new code should use HttpClient. If you maintain an old app that relies on the system-wide default proxy, you can also set WebRequest.DefaultWebProxy once at start-up, but a proxy set explicitly on each request is easier to reason about.

Proxies with IHttpClientFactory and Dependency Injection

ASP.NET Core and worker services

In ASP.NET Core and background workers, clients usually come from IHttpClientFactory. Configure the primary handler for a named client and every instance gets the proxy and its credentials:

C# — named HttpClient with a proxy
builder.Services.AddHttpClient("proxied")
    .ConfigurePrimaryHttpMessageHandler(() => new HttpClientHandler
    {
        Proxy = new WebProxy("http://v2.proxyempire.io:5000")
        {
            Credentials = new NetworkCredential(
                builder.Configuration["Proxy:User"],
                builder.Configuration["Proxy:Password"])
        },
        UseProxy = true
    });

// later, in a service
var client = httpClientFactory.CreateClient("proxied");

Keep the proxy username and password in configuration or a secrets store, not in source code. Anyone who has them can spend your bandwidth.

If you need several proxy sessions or locations in one application, register one named client per session, each with its own username, and pick the right name where you create the client. That keeps each session’s connections and credentials separate.

Fix 407 in curl, Python and Browsers

The same rule everywhere: credentials go to the proxy

curl

Give curl the proxy with -x and its credentials with -U (--proxy-user). Using -u by mistake sends them to the website instead, and the proxy keeps answering 407.

curl — proxy with credentials
curl -x http://v2.proxyempire.io:5000 -U "USERNAME:PASSWORD" https://api.ipify.org

Python requests

Requests takes the credentials inside the proxy URL. URL-encode the password if it contains special characters.

Python — requests through an authenticated proxy
import os
from urllib.parse import quote
import requests

user = os.environ["PROXY_USER"]
password = quote(os.environ["PROXY_PASS"], safe="")
proxy = f"http://{user}:{password}@v2.proxyempire.io:5000"

r = requests.get("https://api.ipify.org",
                 proxies={"http": proxy, "https": proxy}, timeout=30)
print(r.text)

Node.js with axios

Axios takes the proxy and its credentials together in the proxy option. The auth object inside proxy is for the proxy; the top-level auth option is for the website, and mixing them up is a classic cause of 407.

Node.js — axios through an authenticated proxy
import axios from 'axios';

const res = await axios.get('https://api.ipify.org', {
  proxy: {
    protocol: 'http',
    host: 'v2.proxyempire.io',
    port: 5000,
    auth: { username: process.env.PROXY_USER, password: process.env.PROXY_PASS },
  },
});
console.log(res.data);

Java, Puppeteer and browsers

Java disables Basic proxy authentication for HTTPS tunnels by default, which causes 407 even with correct credentials; our Java proxy authentication guide shows the fix. In Puppeteer, credentials go through page.authenticate(); see our Puppeteer proxy guide. Browsers show a sign-in box for the proxy, and tools with a proxy settings screen have their own username and password fields.

How ProxyEmpire Proxy Credentials Work

Why the username changes

Many 407 errors come from credentials that were right yesterday. With ProxyEmpire, the proxy username isn’t only your account name: it also carries the choices you made in the Proxy Manager, such as the proxy type, country, city, rotation mode and session. That’s what lets one host and port serve every location and session type. It also means that when you change any of those settings, the username you need changes with them.

So when a working setup suddenly returns 407, the first question is whether anyone changed the targeting in the dashboard. If they did, copy the new username into your application’s configuration and restart it. If you run several locations or sessions at once, keep one username per client or handler and label them clearly in your configuration, so it’s obvious which one belongs where.

ProxyEmpire proxies use username and password authentication and don’t need your IP to be whitelisted, so the same credentials work from your laptop, a server or a cloud function. The flip side is that anyone who has them can use your bandwidth, so treat them like any other secret: keep them in environment variables or a secrets store, keep them out of logs and screenshots, and rotate them if they leak. The Test proxy settings option in the Proxy Manager is the quickest way to confirm a username and password are valid before you debug your code.

A Checklist That Finds the Cause

Work down the list
  1. Test with curlRun the curl command above with your host, port, username and password. If curl gets 407 too, the credentials are the problem, not your code.
  2. Copy the credentials againTake the username and password fresh from the Proxy Manager, after setting the targeting you want, and check for spaces.
  3. Check where they’re setIn C#, on WebProxy.Credentials; in curl, -U; in Python, inside the proxy URL.
  4. Rule out the system proxyMake sure your code sets its own proxy rather than inheriting one from Windows settings or environment variables.

If curl works but your code doesn’t, compare the host, port and scheme exactly. If curl fails too, use the Test proxy settings option in the Proxy Manager, then contact our 24/7 live chat with the proxy type, the target site and the full error.

Remember

  • 407 comes from the proxy, not the website.
  • Credentials must be attached to the proxy, not the request.
  • With ProxyEmpire, a new targeting setup means a new username.
  • Test with curl first: it separates credential problems from code problems in seconds.

407 Proxy Authentication Required FAQ

Quick answers
What does 407 Proxy Authentication Required mean?

The proxy between you and the website needs a username and password and didn’t receive valid ones, so it refused to forward your request.

What’s the difference between 401 and 407?

401 comes from the website and asks for a login to the site. 407 comes from the proxy and asks for a login to the proxy. They use different headers: WWW-Authenticate and Authorization for 401, Proxy-Authenticate and Proxy-Authorization for 407.

How do I fix 407 in C# HttpClient?

Create a WebProxy with Credentials = new NetworkCredential(user, pass), set it as HttpClientHandler.Proxy with UseProxy = true, and build the HttpClient from that handler.

I set the credentials and still get 407. Why?

Usually the username is out of date or has a stray space, or the credentials are on the wrong object. With ProxyEmpire, copy the username again after changing targeting, and test it with curl.

Does a 407 error mean my IP or the website blocked me?

No. A 407 comes from the proxy before your request ever reaches the website, and it’s always about the proxy login. If a website blocks you, you’ll see its own response instead, such as 403 Forbidden, 429 Too Many Requests or a challenge page.

Why do I get 407 only for HTTPS sites?

For HTTPS, the client first asks the proxy to open a tunnel, and some clients handle authentication differently at that step. Java, for example, disables Basic proxy authentication for HTTPS tunnels by default. Check your runtime’s settings for tunnel authentication, and test the same credentials with curl against an HTTPS URL.

Does WebProxy need BypassProxyOnLocal or other settings?

Not for the fix. The address and Credentials are what matter. BypassProxyOnLocal only controls whether local addresses skip the proxy, which is useful in corporate networks but has nothing to do with a 407.

Can I avoid the password by whitelisting my IP?

ProxyEmpire proxies use username and password authentication, so IP whitelisting isn’t needed and credentials are required. That also means the proxy works from any network or server.

Is it safe to send proxy credentials over HTTP?

Basic authentication only encodes the credentials, it doesn’t encrypt them. Keep them out of code and logs, and rotate them if they leak. The traffic to HTTPS sites stays encrypted inside the proxy tunnel.

References

Sources and documentation
  1. MDN — 407 Proxy Authentication Required. developer.mozilla.org/en-US/docs/Web/HTTP/Reference/Status/407
  2. MDN — Proxy-Authorization header. developer.mozilla.org/en-US/docs/Web/HTTP/Reference/Headers/Proxy-Authorization
  3. Microsoft Learn — HttpClientHandler.Proxy. learn.microsoft.com/en-us/dotnet/api/system.net.http.httpclienthandler.proxy
  4. Microsoft Learn — WebProxy class. learn.microsoft.com/en-us/dotnet/api/system.net.webproxy
  5. Axios — Request config (proxy option). axios-http.com/docs/req_config
  6. curl — manual page (-x, -U). curl.se/docs/manpage.html
  7. Requests — Advanced usage: Proxies. requests.readthedocs.io/en/latest/user/advanced

Proxies that work the first time

Test your setup with the $1.97 trial: 100 MB of residential and 50 MB of mobile bandwidth, HTTP(S) and SOCKS5, a built-in proxy tester in the dashboard, and 24/7 support from real people.

Flexible Pricing Plan

logo purple proxyempire

Our state-of-the-art proxies.

Experience online freedom with our unrivaled web proxy solutions. Pioneering in collecting location specific data at scale, our premium, ethically-sourced network boasts a vast pool of IPs, expansive location choices, high success rate, and versatile pricing. Advance your digital journey with us.

🏘️ Rotating Residential Proxies
  • 30M+ Premium Residential IPs
  •  170+ Countries
    Every residential IP in our network corresponds to an actual desktop device with a precise geographical location. Our residential proxies aare fast and reliable, with 99.9% uptime, and work for a wide range of use cases. You can use Country, Region, City and ISP targeting for our rotating residential proxies.

See our Rotating Residential Proxies

📍 Static Residential Proxies
  • 19 Countries
    Buy a dedicated static residential IP from one of the 19 countries that we offer proxies in. Keep the same IP for a month or longer, while benefiting from their fast speed and stability.

See our Static Residential Proxies

📳 Rotating Mobile Proxies
  • 4M+ Premium Mobile IPs
  •  170+ Countries
    Access millions of clean mobile IPs with precise targeting including Country, Region, City, and Mobile Carrier. Get far fewer IP blocks and CAPTCHAs with our 4G and 5G proxies.

See our Mobile Proxies

📱 Dedicated Mobile Proxies
  • 5+ Countries
  • 50+ Locations
    Get your own dedicated mobile proxy in one of our supported locations, with unlimited bandwidth and unlimited IP changes on demand. A great choice when you need a small number of mobile IPs and a lot of proxy bandwidth.

See our 4G & 5G Proxies

🌐 Rotating Datacenter Proxies
  • 197,000+ IPs Premium IPs
  •  62 Countries
    On a budget and need to do some simple scraping tasks? Our datacenter proxies are the perfect fit! Get started with as little as $2

See our Datacenter Proxies

proxy locations

30M+ rotating IPs

99% uptime - high speed

99.9% uptime.

dedicated support team

24/7 Dedicated Support.

fair price

Fair Pricing.

🏠 Residential Proxies Rotating / Static / Unlimited
📱 Mobile Proxies Rotating and Dedicated
🖥️ Datacenter Proxies Rotating
🌍 IP Pool 30M+ residential + 4M+ mobile IPs
📶 Uptime 99.9% · Live status
💳 Payment Card · PayPal · Crypto · Bank transfer
💬 Support 24/7 live chat · [email protected]