Guide · 5 min read · 2026-10-06

Authenticating to the gateway: credentials and allow-lists

How proxy authentication works, how to encode special characters in credentials, and when to authenticate by source address instead.

A gateway accepts a connection and decides who is asking. There are two ways to tell it: send a username and password with each request, or connect from a source address you have registered in advance. Which one your plan supports is shown against the product in your dashboard.

Username and password

HTTP proxies use the Proxy-Authorization header. Most clients build it for you when the credentials are in the proxy URL. If the password contains characters such as @, :, / or #, the URL parses wrongly unless they are percent-encoded. The usual symptom is a 407 on credentials you know are right.

python: encode before building the URL
from urllib.parse import quote

user = quote("USERNAME", safe="")
password = quote("PASSWORD", safe="")
proxy = f"http://{user}:{password}@GATEWAY_HOST:PORT"

Keep credentials out of source control. Read them from the environment or a secret store, and rotate them if they appear in a log or a ticket.

shell: read from the environment
export PROXY_URL='http://USERNAME:PASSWORD@GATEWAY_HOST:PORT'
curl -x "$PROXY_URL" https://example.com/ -o /dev/null -s -w '%{http_code}\n'

Source-address allow-list

Where your plan supports it, you register the public addresses your workers connect from and send no credentials. This suits clients that cannot send proxy credentials. It needs stable egress: a worker whose public address changes between runs will be refused until the list is updated, and an address shared with other tenants lets them use your access.

Diagnosing a refusal

  • 407: the gateway did not accept the credentials. Check encoding first, then that the credentials belong to the product you are connecting to.
  • Connection refused or a timeout before any response: wrong host or port, or an outbound firewall rule on your side.
  • Works from your laptop, fails from a server: the server's address is not on the allow-list, or egress to the port is blocked.

More guides

Test it on your own targets.

Create an account, run the measurement harness against your real workload, and read the numbers before you commit to anything.