Add your server's public address in the panel, point your software at gw.pyproxy.com:8081, and send no credentials at all. We recognise the address and sign the session in for you. This page covers how to set it up, which address to add, why it is the wrong tool for a laptop, and what every refusal means.
Every PyProxy account has both. They route through the same gateway and draw from the same balance; the only difference is how the gateway recognises you.
| Username & password | IP whitelist | |
|---|---|---|
| Where to connect | gw.pyproxy.com:1111 HTTP(S) gw.pyproxy.com:2222 SOCKS5 | gw.pyproxy.com:8081 HTTP(S) only |
| What you send | The login from your panel, with country and session tags in the username | Nothing. The connecting address is the login |
| Works from | Anywhere: laptop, phone, browser profile, a friend's Wi-Fi | The addresses you listed, and nowhere else |
| Country and sticky | Chosen per line in the username | Chosen per address in the panel |
| Best for | Dynamic connections, antidetect browsers, anything you carry around | Servers, scrapers, CI runners, tools whose config cannot hold a secret safely |
The practical reason to have both: test with a password from your own machine, then whitelist the server once the job goes into production. Same account, same balance, no plan change.
# nothing to hide in this command: the address does the authenticating curl -x http://gw.pyproxy.com:8081 https://api.ipify.org # Python, requests proxies = {"http": "http://gw.pyproxy.com:8081", "https": "http://gw.pyproxy.com:8081"} requests.get("https://example.com", proxies=proxies, timeout=30)
The one a website sees when that machine connects to it. Three addresses get confused with it, and each produces the same refusal:
From any machine, the free IP check tool prints the public address and its provider. If the provider column names a cloud host, you are looking at your server; if it names a home ISP or a mobile carrier, read the next section before whitelisting anything.
Home and mobile connections have dynamic addresses. The ISP hands you one, and swaps it on a reboot, a line drop or simply on a schedule. Whitelisting such an address is a promise the connection cannot keep: the proxy works until the address changes, then every request comes back 407 with the new, unknown address in the body.
Two variants are worse. Behind carrier-grade NAT, common on mobile data and on some fibre providers, you share one public address with hundreds of neighbours; it still rotates, and until it does, everyone behind it is you as far as the whitelist knows. And a VPN on the same machine moves your public address to the VPN's exit, so the entry stops matching the moment the VPN connects or drops.
An entry is not just an address; it carries the targeting that a password user would put in the username. Two servers in one account can have different countries and different session modes, and each connects with the same empty credentials.
Sticky mode ties the exit IP to the connecting machine. Two whitelisted servers with sticky on receive two different exits and keep them; they never share one, and you never see one server's session hop because the other made a request. The exit is held for as long as the network keeps it alive, and a new one is issued when it goes.
Need a different country for one job on the same server? Change the entry in the panel; the next connection, within fifteen seconds, uses the new setting. For several countries from one machine at the same time, use password logins on port 1111, where each line carries its own tag.
| Limit | Value | Why |
|---|---|---|
| Addresses per account | 10 | Enough for a small fleet; a whitelist of hundreds is a sign that credentials were the right tool |
| Address type | IPv4 only, single addresses | Ranges (CIDR) are not accepted; every machine is listed on its own |
| Protocols | HTTP and HTTPS on port 8081 | SOCKS5 needs username and password on port 2222 for now |
| Time to apply | Under 15 seconds | Add, change or remove; a removed address stops working within that window |
| Billing | Same balance, same rate | Traffic leaves through the same gateway and is counted once |
| Traffic required | A residential package on the account | The address recognises you, the package pays for the bytes |
Port 8081 answers refusals with a plain-text body rather than a bare code, because a client with no password to offer would otherwise just retry for ever. Read the body.
| What you see | What it means | Fix |
|---|---|---|
| 407 — “this address is not on your whitelist. Connecting address: 203.0.113.9” | We saw the request, but the address it came from is on nobody's list | Add the address printed in the body, exactly as printed. If it differs from what you added before, your connection has rotated |
| 407 — “Your account has no residential traffic to route” | The address is known, but the account has no package to bill the bytes to | Buy a residential package; the entry starts working as soon as it lands |
| Timeout, no answer at all | Wrong port, or a firewall between you and the gateway | Confirm host gw.pyproxy.com, port 8081, type HTTP; try curl -v from the same machine |
| Works with curl, fails in the application | The application sends its own stale credentials, or uses SOCKS5 | Clear the username and password fields; switch the proxy type to HTTP |
| Every request exits from a different country | The entry has no country set | Edit the entry and set a two-letter country code |
| The exit changes mid-session | Sticky is off for that entry, or the held exit expired | Turn sticky on; expect a new exit after prolonged use, as with any residential session |
Whitelisting removes a secret from a config file, and that is its whole advantage. Everything else favours credentials: they work from any address, carry per-line targeting, cover SOCKS5, and never break because an ISP rotated something at 3 a.m. Antidetect browser profiles in particular should use credentials — a profile is meant to look like an independent person, and a whole fleet of profiles authenticating from one whitelisted office address is the opposite of that. The SOCKS5 setup guide covers the per-device steps for the password route.
Related: What is my IP · SOCKS5 on PyProxy · Locations · FAQ
The public address your traffic leaves from: the one a website sees, not a 192.168.x or 10.x address from your router. The IP authentication card in the panel shows the address you are connecting from right now, and the IP check tool shows it from any machine.
Your connection's public address changed. Home and mobile connections are dynamic and rotate on reboots, line drops or a schedule. Use username and password on ports 1111 and 2222 from those, and keep whitelisting for servers with a fixed address.
Not yet. The password-free port 8081 speaks HTTP and HTTPS. SOCKS5 is on port 2222 and takes your username and password.
Ten IPv4 addresses per account, each with its own country and sticky setting. Ranges are not accepted; add each machine on its own.
No. It leaves through the same gateway and is counted against the same balance as a session with a password. Nothing is metered twice.