A gateway accepts a connection and decides who is asking. There are two ways to tell it: send a username and password with each request, or connect from a source address you have registered in advance. Which one your plan supports is shown against the product in your dashboard.
Username and password
HTTP proxies use the Proxy-Authorization header. Most clients build it for you when the credentials are in the proxy URL. If the password contains characters such as @, :, / or #, the URL parses wrongly unless they are percent-encoded. The usual symptom is a 407 on credentials you know are right.
from urllib.parse import quote
user = quote("USERNAME", safe="")
password = quote("PASSWORD", safe="")
proxy = f"http://{user}:{password}@GATEWAY_HOST:PORT"Keep credentials out of source control. Read them from the environment or a secret store, and rotate them if they appear in a log or a ticket.
export PROXY_URL='http://USERNAME:PASSWORD@GATEWAY_HOST:PORT'
curl -x "$PROXY_URL" https://example.com/ -o /dev/null -s -w '%{http_code}\n'Source-address allow-list
Where your plan supports it, you register the public addresses your workers connect from and send no credentials. This suits clients that cannot send proxy credentials. It needs stable egress: a worker whose public address changes between runs will be refused until the list is updated, and an address shared with other tenants lets them use your access.
Diagnosing a refusal
- 407: the gateway did not accept the credentials. Check encoding first, then that the credentials belong to the product you are connecting to.
- Connection refused or a timeout before any response: wrong host or port, or an outbound firewall rule on your side.
- Works from your laptop, fails from a server: the server's address is not on the allow-list, or egress to the port is blocked.