What a 407 or 403 message means
Updated 2 min read
The numbers 407 and 403 are two of the most common messages on a first connection. They look alike but mean different things, so the first question is always: who sent it, the proxy or the website?
Step 1: find out who replied
Run your request with curl -v:
curl -v -x "http://USERNAME:PASSWORD@HOST:PORT" https://api.ipify.org
For an HTTPS page, the proxy first opens a private tunnel to the website. You see a line like this once it has succeeded:
< HTTP/1.1 200 Connection established
A reply that comes before that line was sent by the proxy. A reply that comes after it was sent by the website.
Step 2a: if it was a 407
407 Proxy Authentication Required means the proxy itself replied: it did not receive your login, or did not accept it. Please check these in order:
- The username and password match the proxy's page in the dashboard exactly, with no spaces or line breaks.
- If the login is inside a web address, special characters in the password are percent-encoded (
@becomes%40,:becomes%3A). - Your program really sends the login. Some tools send it only after a first
407, so one407in the log does not mean something is broken. - You did not generate a new password recently. The old one stops working straight away.
More on logins: Signing in to the proxy with your username and password.
Step 2b: if it was a 403
403 Forbidden can come from the proxy or from the website, and the fix is different.
If the proxy refused you, check that it is still Active on its page in the dashboard, and has bandwidth and time left.
If the website sent it, the tunnel opened and the proxy did its job. The website is refusing that exit address or that request. You can try another exit address, a slower pace, or requests that look more like an ordinary browser. If it carries on, If a website blocks your proxy, tell us this much lists what to send us.
If you use the IP allowlist
A proxy set to IP allowlist does not accept its username and password. Whichever of the two codes you see, check that the address you connect from right now is on the proxy's list. See Letting the proxy recognise your IP address.
Not sure which one it was?
Write to support@proxypanda.io with the curl -v output. Before you send it, remove your password and delete any line that contains Proxy-Authorization, because that line carries your login in encoded form.