A 407 Proxy Authentication Required error means your request reached the proxy, but the proxy didn’t get valid credentials, so it refused to forward it. In C# it usually appears as “The remote server returned an error: (407) Proxy Authentication Required”. This guide explains what the proxy is asking for, shows the working fix for .NET HttpClient and the older HttpWebRequest, gives the equivalent fixes for curl and Python, and lists the real-world causes we see most with residential proxies.
The short version
Give the proxy its username and password on the proxy object, not on the request: in C#, create a WebProxy with Credentials = new NetworkCredential(user, pass) and pass it to HttpClientHandler.Proxy. If you already do that and still get 407, the credentials are wrong or out of date. With ProxyEmpire, the username changes when you change targeting, so copy it again from the dashboard.
What 407 Proxy Authentication Required Means
The proxy wants credentials before it forwards anythingHTTP status code 407 is the proxy’s version of 401. MDN describes it as a request that didn’t succeed because it lacks valid authentication credentials for the proxy server between the client and the target. The proxy sends a Proxy-Authenticate header saying how it expects you to log in, and the client has to repeat the request with a Proxy-Authorization header carrying the credentials.
client -> proxy GET / CONNECT (no credentials)
proxy -> client HTTP/1.1 407 Proxy Authentication Required
Proxy-Authenticate: Basic realm="..."
client -> proxy same request + Proxy-Authorization: Basic <base64 user:pass>
proxy -> target request forwarded, response comes back
Two things follow from that. First, the error comes from the proxy, not the website you’re trying to reach, so changing anything about the target URL won’t fix it. Second, the fix is always about the proxy’s credentials: whether your client sends them, whether it sends them to the proxy rather than the target, and whether they’re correct.
Common Causes of a 407 Error
In order of how often we see them| Cause | What to check |
|---|---|
| Credentials never sent to the proxy | The username and password are set on the request or the client, not on the proxy object. In .NET they belong on WebProxy.Credentials. |
| Out-of-date username | With ProxyEmpire, the username encodes your targeting and session. Change the country or session and the username changes too. |
| Typo or hidden space | A trailing space or line break copied with the password. Copy both values again from the Proxy Manager. |
| Special characters in a URL | If credentials are written into a proxy URL, characters such as @, : and / must be URL-encoded. |
| The system proxy is used instead | The client picked up a proxy from Windows settings or environment variables, which doesn’t have your credentials. |
| Client refuses Basic auth | Some runtimes disable Basic authentication for HTTPS tunnels by default. Java is the best-known example. |
Fix 407 Proxy Authentication Required in C# HttpClient
Credentials on the WebProxy, proxy on the handlerIn modern .NET, HttpClient gets its proxy from its handler. Microsoft’s documentation for HttpClientHandler.Proxy explains that when you set this property, it overrides any proxy from the machine or application configuration, so your code controls exactly which proxy and credentials are used.
using System.Net;
var proxy = new WebProxy("http://v2.proxyempire.io:5000")
{
Credentials = new NetworkCredential(
Environment.GetEnvironmentVariable("PROXY_USER"),
Environment.GetEnvironmentVariable("PROXY_PASS"))
};
var handler = new HttpClientHandler
{
Proxy = proxy,
UseProxy = true
};
using var client = new HttpClient(handler);
string ip = await client.GetStringAsync("https://api.ipify.org");
Console.WriteLine(ip); // should print the proxy's IP, not yours
Notes on getting it right:
- Put the credentials on
WebProxy.Credentials. SettingHttpClientHandler.Credentialsinstead sends them to the target site, not the proxy, and you keep getting 407. - Create the handler once and reuse the client. A new
HttpClientper request wastes connections. If you need different proxy sessions, keep one client per session. - HTTPS works through the same proxy. The client opens a tunnel to the target with a
CONNECTrequest and authenticates to the proxy for it. The traffic to the site stays encrypted end to end. - SocketsHttpHandler works the same way. It also has a
Proxyproperty that takes the sameWebProxyobject.
Fix “The remote server returned an error: (407)” in HttpWebRequest
Older .NET Framework codeThe exact message “The remote server returned an error: (407) Proxy Authentication Required” comes from a WebException, which is what HttpWebRequest throws. It’s common in older .NET Framework applications. The fix is the same idea: set a WebProxy with credentials on the request.
using System.IO;
using System.Net;
var request = (HttpWebRequest)WebRequest.Create("https://api.ipify.org");
request.Proxy = new WebProxy("http://v2.proxyempire.io:5000")
{
Credentials = new NetworkCredential("USERNAME", "PASSWORD")
};
using (var response = (HttpWebResponse)request.GetResponse())
using (var reader = new StreamReader(response.GetResponseStream()))
{
Console.WriteLine(reader.ReadToEnd());
}
WebRequest and HttpWebRequest are marked obsolete in modern .NET, so new code should use HttpClient. If you maintain an old app that relies on the system-wide default proxy, you can also set WebRequest.DefaultWebProxy once at start-up, but a proxy set explicitly on each request is easier to reason about.
Proxies with IHttpClientFactory and Dependency Injection
ASP.NET Core and worker servicesIn ASP.NET Core and background workers, clients usually come from IHttpClientFactory. Configure the primary handler for a named client and every instance gets the proxy and its credentials:
builder.Services.AddHttpClient("proxied")
.ConfigurePrimaryHttpMessageHandler(() => new HttpClientHandler
{
Proxy = new WebProxy("http://v2.proxyempire.io:5000")
{
Credentials = new NetworkCredential(
builder.Configuration["Proxy:User"],
builder.Configuration["Proxy:Password"])
},
UseProxy = true
});
// later, in a service
var client = httpClientFactory.CreateClient("proxied");
Keep the proxy username and password in configuration or a secrets store, not in source code. Anyone who has them can spend your bandwidth.
If you need several proxy sessions or locations in one application, register one named client per session, each with its own username, and pick the right name where you create the client. That keeps each session’s connections and credentials separate.
Fix 407 in curl, Python and Browsers
The same rule everywhere: credentials go to the proxycurl
Give curl the proxy with -x and its credentials with -U (--proxy-user). Using -u by mistake sends them to the website instead, and the proxy keeps answering 407.
curl -x http://v2.proxyempire.io:5000 -U "USERNAME:PASSWORD" https://api.ipify.org
Python requests
Requests takes the credentials inside the proxy URL. URL-encode the password if it contains special characters.
import os
from urllib.parse import quote
import requests
user = os.environ["PROXY_USER"]
password = quote(os.environ["PROXY_PASS"], safe="")
proxy = f"http://{user}:{password}@v2.proxyempire.io:5000"
r = requests.get("https://api.ipify.org",
proxies={"http": proxy, "https": proxy}, timeout=30)
print(r.text)
Node.js with axios
Axios takes the proxy and its credentials together in the proxy option. The auth object inside proxy is for the proxy; the top-level auth option is for the website, and mixing them up is a classic cause of 407.
import axios from 'axios';
const res = await axios.get('https://api.ipify.org', {
proxy: {
protocol: 'http',
host: 'v2.proxyempire.io',
port: 5000,
auth: { username: process.env.PROXY_USER, password: process.env.PROXY_PASS },
},
});
console.log(res.data);
Java, Puppeteer and browsers
Java disables Basic proxy authentication for HTTPS tunnels by default, which causes 407 even with correct credentials; our Java proxy authentication guide shows the fix. In Puppeteer, credentials go through page.authenticate(); see our Puppeteer proxy guide. Browsers show a sign-in box for the proxy, and tools with a proxy settings screen have their own username and password fields.
How ProxyEmpire Proxy Credentials Work
Why the username changesMany 407 errors come from credentials that were right yesterday. With ProxyEmpire, the proxy username isn’t only your account name: it also carries the choices you made in the Proxy Manager, such as the proxy type, country, city, rotation mode and session. That’s what lets one host and port serve every location and session type. It also means that when you change any of those settings, the username you need changes with them.
So when a working setup suddenly returns 407, the first question is whether anyone changed the targeting in the dashboard. If they did, copy the new username into your application’s configuration and restart it. If you run several locations or sessions at once, keep one username per client or handler and label them clearly in your configuration, so it’s obvious which one belongs where.
ProxyEmpire proxies use username and password authentication and don’t need your IP to be whitelisted, so the same credentials work from your laptop, a server or a cloud function. The flip side is that anyone who has them can use your bandwidth, so treat them like any other secret: keep them in environment variables or a secrets store, keep them out of logs and screenshots, and rotate them if they leak. The Test proxy settings option in the Proxy Manager is the quickest way to confirm a username and password are valid before you debug your code.
A Checklist That Finds the Cause
Work down the list- Test with curlRun the curl command above with your host, port, username and password. If curl gets 407 too, the credentials are the problem, not your code.
- Copy the credentials againTake the username and password fresh from the Proxy Manager, after setting the targeting you want, and check for spaces.
- Check where they’re setIn C#, on
WebProxy.Credentials; in curl,-U; in Python, inside the proxy URL. - Rule out the system proxyMake sure your code sets its own proxy rather than inheriting one from Windows settings or environment variables.
If curl works but your code doesn’t, compare the host, port and scheme exactly. If curl fails too, use the Test proxy settings option in the Proxy Manager, then contact our 24/7 live chat with the proxy type, the target site and the full error.
Remember
- 407 comes from the proxy, not the website.
- Credentials must be attached to the proxy, not the request.
- With ProxyEmpire, a new targeting setup means a new username.
- Test with curl first: it separates credential problems from code problems in seconds.
407 Proxy Authentication Required FAQ
Quick answersWhat does 407 Proxy Authentication Required mean?
The proxy between you and the website needs a username and password and didn’t receive valid ones, so it refused to forward your request.
What’s the difference between 401 and 407?
401 comes from the website and asks for a login to the site. 407 comes from the proxy and asks for a login to the proxy. They use different headers: WWW-Authenticate and Authorization for 401, Proxy-Authenticate and Proxy-Authorization for 407.
How do I fix 407 in C# HttpClient?
Create a WebProxy with Credentials = new NetworkCredential(user, pass), set it as HttpClientHandler.Proxy with UseProxy = true, and build the HttpClient from that handler.
I set the credentials and still get 407. Why?
Usually the username is out of date or has a stray space, or the credentials are on the wrong object. With ProxyEmpire, copy the username again after changing targeting, and test it with curl.
Does a 407 error mean my IP or the website blocked me?
No. A 407 comes from the proxy before your request ever reaches the website, and it’s always about the proxy login. If a website blocks you, you’ll see its own response instead, such as 403 Forbidden, 429 Too Many Requests or a challenge page.
Why do I get 407 only for HTTPS sites?
For HTTPS, the client first asks the proxy to open a tunnel, and some clients handle authentication differently at that step. Java, for example, disables Basic proxy authentication for HTTPS tunnels by default. Check your runtime’s settings for tunnel authentication, and test the same credentials with curl against an HTTPS URL.
Does WebProxy need BypassProxyOnLocal or other settings?
Not for the fix. The address and Credentials are what matter. BypassProxyOnLocal only controls whether local addresses skip the proxy, which is useful in corporate networks but has nothing to do with a 407.
Can I avoid the password by whitelisting my IP?
ProxyEmpire proxies use username and password authentication, so IP whitelisting isn’t needed and credentials are required. That also means the proxy works from any network or server.
Is it safe to send proxy credentials over HTTP?
Basic authentication only encodes the credentials, it doesn’t encrypt them. Keep them out of code and logs, and rotate them if they leak. The traffic to HTTPS sites stays encrypted inside the proxy tunnel.
References
Sources and documentation- MDN — 407 Proxy Authentication Required. developer.mozilla.org/en-US/docs/Web/HTTP/Reference/Status/407
- MDN — Proxy-Authorization header. developer.mozilla.org/en-US/docs/Web/HTTP/Reference/Headers/Proxy-Authorization
- Microsoft Learn —
HttpClientHandler.Proxy. learn.microsoft.com/en-us/dotnet/api/system.net.http.httpclienthandler.proxy - Microsoft Learn —
WebProxyclass. learn.microsoft.com/en-us/dotnet/api/system.net.webproxy - Axios — Request config (
proxyoption). axios-http.com/docs/req_config - curl — manual page (
-x,-U). curl.se/docs/manpage.html - Requests — Advanced usage: Proxies. requests.readthedocs.io/en/latest/user/advanced
Proxies that work the first time
Test your setup with the $1.97 trial: 100 MB of residential and 50 MB of mobile bandwidth, HTTP(S) and SOCKS5, a built-in proxy tester in the dashboard, and 24/7 support from real people.














