Short answers
What does HTTP 407 mean?
The HTTP status means Proxy Authentication Required. During HTTPS CONNECT, it means the tunnel was refused before the destination request could be sent through it. Portproof also documents 407 for an exhausted balance, so the gateway error code matters.
Why do credentials work in curl but not in Playwright?
The clients may use different settings. In Playwright, put the server, username and password in the proxy object. httpCredentials authenticates a website, not the proxy. Repeat a page navigation from the intended browser context.
Should I encode my proxy password?
Encode the username and password components once when building a proxy URL. Do not encode the full URL. When entering the password at curl’s interactive prompt, enter the actual password rather than a URL-encoded value.
Can a 407 mean that my GB ran out?
Yes. The documented E_CAP_EXCEEDED code indicates exhausted or expired traffic. Check the account balance and validity before regenerating credentials. E_AUTH_INVALID instead points to the username base or password.
Will Python Requests return response.status_code 407?
A plain HTTP request through a proxy can receive a 407 response. A refused CONNECT for an HTTPS destination instead raises ProxyError before a destination response exists. Checking only response.status_code misses that failure.
Identify the response that failed
Proxy authentication uses Proxy-Authenticate and Proxy-Authorization; destination authentication uses different headers. For an HTTPS destination, the client first asks the HTTP gateway to open a CONNECT tunnel. If that stage is refused, changing the destination’s login cannot repair it. See the HTTP 407 definition.
Keep the CONNECT status separate from the destination status. In the check below, connect=407 target=000 means no destination HTTP response was received. The value 000 is curl’s missing-status marker, not an HTTP status sent by a server. For other tunnel failures, use the CONNECT troubleshooting guide.
If a browser or device asks for a username and password without showing an HTTP status, start with the proxy sign-in prompt guide. It helps identify the network setting and the credentials that prompt expects. For a different message, use the proxy error index.
Five checks before changing a password
- Read the balance and error code. E_CAP_EXCEEDED needs a balance or validity check; repeating the same password will not fix it.
- Compare the complete generated username and current proxy password with the connection builder. Your website password and API key are different credentials.
- Check the HTTP or SOCKS5 scheme and matching port. A protocol mismatch may fail before authentication; it is not evidence of a bad password.
- Check how your client receives credentials. URL components need encoding; separate authentication fields and the interactive curl prompt need the original values.
- Check the running worker. A process can retain an older secret after it changes in the dashboard or deployment configuration. Refresh that worker before testing again.
A malformed username is documented as 400 E_USERNAME_PARSE, not as a 407. Some clients group different connection failures under a proxy error. Keep the exact status or exception class rather than guessing from a generic message.
Check the generated username
Use the builder output as the starting point. It includes the account prefix, pool, country and selected rotation settings. Keep the pool and country unchanged if they remain available. Check current availability on locations.
- Check the full account prefix and the current proxy password together.
- Keep username tokens lower case and preserve their generated order.
- For a sticky session, use an accepted session name and the same generated username throughout the job.
- Check for accidental spaces or line breaks from copying; do not alter whitespace that belongs to the password.
The setup reference documents the fields. The rotation guide explains session lifetime and why a retained device can still change its IP.
Repeat one controlled client check
In an interactive terminal, replace the example username with the complete one from the builder. Enter the password when curl asks; leave it out of the command and proxy URL. This records the two response stages without printing the response body.
curl --disable --silent --show-error --noproxy '' --connect-timeout 5 --max-time 15 -o /dev/null -w 'connect=%{http_connect} target=%{response_code}\n' \
-x "http://gw.portproof.org:7000" \
--proxy-user "USERNAME-mbl-us-rot-auto10" \
https://api.portproof.org/v1/echo-ipA local check with curl 8.7.1 recorded connect=407 target=000 and exit 56 for rejected HTTPS tunnel authentication. The plain HTTP check returned 407 with exit 0 because no HTTP-failure option was set. Neither exit 0 nor receiving a body proves success. These were synthetic loopback checks, not a live-pool benchmark.
Our Requests 2.34.2 fixture likewise recorded a 407 response for rejected plain HTTP proxy authentication, but ProxyError for rejected HTTPS CONNECT. The Python Requests example handles exceptions and encodes credentials once. Adding only if response.status_code == 407 misses a failed tunnel.
Use the complete Node.js fetch, HTTPX or Playwright example for those clients. Each configures its own transport. A passing curl request does not prove that an application follows the same route.
Use the gateway code to choose the next step
| Status and code | Next step |
|---|---|
| 407 · E_AUTH_INVALID | Check the complete username and current proxy password. |
| 407 · E_CAP_EXCEEDED | Check remaining traffic and validity; changing the password does not restore GB. |
| 400 · E_USERNAME_PARSE | Rebuild the username and check accepted tokens. |
| 429 · E_RATE_LIMITED_CONN | Reduce concurrent connections and delay any permitted retry. |
| 429 · E_SESSION_LIMIT | Review named sessions and reuse the intended session within one job. |
| 502 · E_NO_STOCK_COUNTRY | Check current availability for that pool and country. |
A client may expose only the tunnel status, without the gateway’s detailed code. Check balance and configuration separately when that happens; status alone cannot distinguish every cause. Checks consume traffic, so keep the endpoint small and avoid an automatic retry loop.
Replace a password deliberately
Regenerate an exposed password, rather than treating every 407 as a reason to replace it. The traffic API documents roughly thirty seconds of overlap for the previous password. Arrange the rollout, refresh each worker’s secret and check one request before resuming the queue; do not assume every worker updates within that window.
Regeneration leaves the username and balance unchanged. The API reference covers the operation. Keep credential-bearing responses and traces out of shared logs. If the refreshed credential is still rejected, stop and investigate rather than regenerating it repeatedly.
Keep the evidence needed for support
- Record the time and time zone, client version, protocol and failing stage.
- Keep the gateway code when available, CONNECT status and destination status separately.
- Describe pool, country and rotation settings without sending the password, API key or credential URL.
After the echo check succeeds, test one authorised application request and its expected content before restarting the workload. See pricing and traffic accounting if the balance was exhausted.
What is not allowed
Use these checks for your own services or permitted QA, price monitoring, ad verification and research. Respect access rules and rate limits. A proxy credential does not grant permission to access a website. See the acceptable-use policy.