Authentication
Username/password and IP-whitelist proxy authentication, residential credentials, and API keys for the REST API — what each is for and how they interact.
On this page
Proxuno uses two independent kinds of credentials:
- Proxy credentials authenticate traffic sent through a gateway (mobile, residential, static ISP).
- API keys authenticate calls to the REST API at
https://proxuno.com/api/v1.
Your dashboard password is never used for either.
Proxy authentication modes#
| Mode | How it works | Best for |
|---|---|---|
| Username & password | Credentials are sent with every connection (HTTP Proxy-Authorization: Basic … or SOCKS5 username/password). |
Scripts, scrapers, antidetect browsers, anything running on changing or shared IPs. |
| IP whitelist | Connections from your registered IPs are accepted without credentials. | Tools that cannot send proxy credentials (some Selenium setups, legacy software, mobile apps). |
Both modes are active at the same time for mobile and static ISP proxies: a connection with valid credentials is always accepted, and a connection without credentials is accepted when its source IP is on your whitelist. The Proxy authentication setting in Settings only changes which line format the dashboard copies and exports by default.
Credentials per product#
| Product | Username | Password | Scope |
|---|---|---|---|
| Mobile 4G/5G | m_ + 8 lowercase letters and digits |
16 characters | one proxy |
| Static ISP | s_ + 8 characters |
16 characters | one IP |
| Rotating residential | <login>-country-<cc>[…] |
16 characters | the whole account |
Mobile and static passwords can be regenerated per proxy from its page. The residential password is shared by every residential endpoint you generate; regenerating it in Residential → Credentials invalidates all existing residential lines immediately.
What happens with wrong credentials#
- HTTP proxies answer
407 Proxy Authentication Required. Most clients retry once and then fail. - SOCKS5 closes the handshake with status
0x01(general failure) after the authentication sub-negotiation. - Expired proxies reject every connection, including whitelisted ones. Renew the proxy to restore access — credentials do not change on renewal.
Special characters. Usernames and passwords only contain letters, digits,
_and-, so they never need URL-encoding inhttp://user:pass@host:portURLs.
API keys#
API keys are created in Dashboard → API. A key looks like pxl_live_ followed by 32 letters and digits and is shown once, at creation — store it in a secret manager or an environment variable. Up to 10 active keys per account; revoke unused ones.
Send the key in either header:
curl https://proxuno.com/api/v1/me -H "Authorization: Bearer $PROXUNO_API_KEY"
import os, requests
r = requests.get("https://proxuno.com/api/v1/me", headers={"X-API-Key": os.environ["PROXUNO_API_KEY"]}, timeout=30)
print(r.json())
const res = await fetch("https://proxuno.com/api/v1/me", {
headers: { Authorization: `Bearer ${process.env.PROXUNO_API_KEY}` },
});
console.log(await res.json());
A missing key returns 401 with code unauthorized; a revoked or malformed key returns 401 as well. Keys carry the full permissions of the account that created them — they can rotate IPs and change settings, but cannot place orders, withdraw balance or change the account password.
Key hygiene#
- Use one key per application or server, named after it, so you can revoke one without touching the others.
- The API page shows when and from which IP each key was last used.
- Never embed a key in client-side code, a browser extension or a mobile app.
- If a key leaks, revoke it first, then create a new one. Revocation is immediate.
Two-factor authentication#
TOTP two-factor authentication (Google Authenticator, Aegis, 1Password, Bitwarden…) protects dashboard logins. It does not apply to proxy or API traffic, which is why API keys must be treated as secrets in their own right. Enable it in Settings.
Something unclear, outdated or wrong on this page? Tell us — documentation issues are fixed in the next release at the latest.
Report an issue with this page