# IP whitelist authentication
Source: https://proxuno.com/docs/ip-whitelist
Updated: 2026-03-10

Getting started

Authorise your servers' IPv4/IPv6 addresses or CIDR ranges so mobile and static ISP proxies accept connections without a username and password.

Updated 10 Mar 2026 2 min read API v1

### On this page

- [Scope](#scope)
- [Add an address](#add-an-address)
- [Connect without credentials](#connect-without-credentials)
- [Good practice](#good-practice)
- [Troubleshooting](#troubleshooting)

IP whitelisting lets a tool connect to `host:port` with no credentials at all. It has been available since September 2021 and is the simplest option for software that cannot send proxy credentials.

## Scope[#](#scope)

| Product | Whitelist supported | Notes |
| --- | --- | --- |
| Mobile 4G/5G | Yes | Applies to every mobile proxy of the account. |
| Static ISP | Yes | Applies to every static IP of the account. |
| Rotating residential | No | Targeting (country, city, session) is encoded in the username, so residential traffic always authenticates with username and password. |

## Add an address[#](#add-an-address)

- Open [Settings → Proxy access → IP whitelist](/dashboard/settings#access).
- Enter a single IPv4 or IPv6 address (`198.51.100.24`, `2001:db8:4::17`) or a CIDR range (`198.51.100.0/28`) and an optional label such as "scraper-01 (Hetzner FSN1)". Up to 20 entries per account; IPv4 ranges up to `/24`, IPv6 ranges up to `/48`.
- Save. The entry is active on every gateway within 60 seconds.

To find the public IP your server uses for outgoing traffic, run from that server:

cURLCopy

```bash
curl -4 https://api.ipify.org
```

Private and reserved ranges (`10.0.0.0/8`, `172.16.0.0/12`, `192.168.0.0/16`, IPv6 link-local and unique-local addresses) are rejected: the gateways only ever see your public address.

## Connect without credentials[#](#connect-without-credentials)

Once your IP is whitelisted, drop the `user:pass@` part:

cURLCopy

```bash
curl -x http://fr.mobile.gw.proxuno.com:10421 https://api.ipify.org?format=json
```

Export lines in the `host:port` format from the proxy list (**Export → host:port (IP whitelist)**) or set **Proxy authentication → IP whitelist** in Settings so the dashboard copies whitelist lines by default.

## Good practice[#](#good-practice)

- **Keep ranges narrow.** A `/24` on a shared hosting network authorises your neighbours too. Prefer single addresses or the smallest range your provider guarantees.
- **Avoid dynamic home connections.** If your ISP changes your IP, traffic stops with `407` until you update the list. Use credentials instead.
- **Credentials keep working.** Whitelisting does not disable username/password authentication; a leaked password still needs to be regenerated.
- **Label entries.** Every addition and removal is recorded in your account security log (kept 90 days), and labels make audits faster.

## Troubleshooting[#](#troubleshooting)

| Symptom | Likely cause |
| --- | --- |
| `407 Proxy Authentication Required` from a whitelisted server | The server leaves through another IP (IPv6, NAT gateway, VPN). Check with `curl -4 https://api.ipify.org` and `curl -6 https://api64.ipify.org`. |
| Works from one machine, not another in the same office | Different egress IPs per network segment — whitelist the other address or use credentials. |
| Residential requests fail without credentials | Expected: residential traffic always needs username and password. |

Something unclear, outdated or wrong on this page? Tell us — documentation issues are fixed in the next release at the latest.

[Report an issue with this page](/contact?topic=support&subject=Documentation%20issue%3A%20IP%20whitelist%20authentication)
