Skip to content
Tutorials

How to Fix Proxy Error 407 (2026)

HTTP error 407 means the proxy rejected your credentials. Here is how to fix it in code, curl, and your browser.

Rectangle Zenezen
October 9, 2026 4 min read
How to Fix Proxy Error 407 (2026)
Click Here to Add Proxyon as a Trusted Source Add as a preferred source

Don't want to read?

Time is a precious resource, get the insights you need using your favorite AI chat.


What HTTP Error 407 Means

What HTTP Error 407 Means

A proxy that requires authentication answers unauthenticated requests with status 407 and a Proxy-Authenticate header naming the scheme it wants, usually Basic. Your client repeats the request with a Proxy-Authorization header. The exchange is defined in RFC 9110.

ABAP
HTTP/1.1 407 Proxy Authentication Required
Proxy-Authenticate: Basic realm="proxy"
Content-Length: 0

The keyword here is proxy. A 401 comes from the website. A 407 means the proxy stopped the request, so the fix always sits between you and the proxy.

You only see that response as a normal 407 for a plain http:// target. For an https:// target, your client first sends CONNECT to open a tunnel, and the proxy rejects that CONNECT with 407 before any TLS handshake. Most libraries surface this as an exception, not a response: requests raises ProxyError('Unable to connect to proxy', OSError('Tunnel connection failed: 407 Proxy Authentication Required')), httpx raises httpx.ProxyError: 407 Proxy Authentication Required, and curl prints CONNECT tunnel failed, response 407.


How to Fix Proxy Error 407 in Your Code

How to Fix Proxy Error 407 in Your Code

Put the credentials inside the proxy URL and let the library build the header. A manual Proxy-Authorization request header fails on HTTPS targets because request headers travel inside the encrypted tunnel, and the proxy only sees a CONNECT with no credentials.

PYTHON
import requests
from urllib.parse import quote

user = "your_username"
password = quote("p@ss:word/2026", safe="")  # encodes @ : / # ? before use
proxy = f"http://{user}:{password}@HOST:PORT"  # host and port from your dashboard

try:
    r = requests.get(
        "https://httpbin.org/ip",
        proxies={"http": proxy, "https": proxy},
        timeout=15,
    )
    print(r.status_code, r.json())
except requests.exceptions.ProxyError as e:
    print("Proxy rejected the credentials:", e)

The quote() call matters more than it sounds. Requests parses the proxy URL before building the header, so a raw /, ?, #, or % in the password changes where the URL splits. The proxy formatter converts between user:pass@host:port and host:port:user:pass without hand edits.

For curl, pass the proxy with -x and the credentials with -U. curl splits on the first colon and builds the header itself, so special characters are safe.

ABAP
curl -x http://HOST:PORT -U "your_username:p@ss:word/2026" https://httpbin.org/ip

Also Read: How to Set Up Rotating Proxies for Web Scraping


When the Credentials Are Right, and You Still Get 407

When the Credentials Are Right and You Still Get 407

Two causes remain. The first is stale environment variables. Requests, curl, pip, and git all read HTTPS_PROXY and its siblings, so an old export with a rotated password routes every tool through a proxy you forgot about. Run env | grep -i proxy and unset what you find.

The second is IP whitelisting. If your account authenticates by IP, the proxy only accepts traffic from the address you registered. A new network, a redeployed cloud instance, or an IPv6 route when you whitelisted IPv4 all trigger it. Check your public IP and update the whitelist. Proxyon supports both methods on residential proxies and datacenter proxies, and username/password is safer for code that runs from more than one machine.


Fixing HTTP Error 407 in Your Browser

Fixing HTTP Error 407 in Your Browser

Chrome and Edge show HTTP ERROR 407 when the system proxy demands credentials the browser cannot supply. With no proxy you set up, that means a leftover setting: a manual proxy from an old tool, a PAC script, or a VPN or antivirus filter acting as a local proxy. On Windows, open Settings, Network & Internet, Proxy, and turn off both the setup script and the manual proxy.

On a work or school network, the proxy is real, and the fix is your domain credentials from IT. If you set it up yourself for a Proxyon plan, re-enter the dashboard username and password at the prompt.

Also Read: How to Use a Proxy Server on Any Device


FAQ Section

FAQ

Is HTTP error 407 the same as 401?

No. A 401 comes from the website and carries a WWW-Authenticate challenge. A 407 comes from the proxy and carries Proxy-Authenticate. If you see 407, the website never received your request.

Why does curl say "CONNECT tunnel failed, response 407"?

Because the target was HTTPS. curl asked the proxy to open a tunnel with CONNECT, and the proxy refused with 407 before any data reached the site. Older curl builds print Received HTTP code 407 from proxy after CONNECT for the same failure. Add -U user:pass or fix the credentials in the -x URL.

Can Cloudflare or the website's server return a 407?

Not on their own. Cloudflare's documentation states that it passes a 407 through from an upstream proxy but does not generate one. A 407 always originates from a forward proxy between you and the site.

Does the proxy URL need https:// for HTTPS websites?

No. Keep http:// for an HTTP proxy and socks5:// for SOCKS5. The scheme describes the hop to the proxy. HTTPS to the website is carried inside the CONNECT tunnel.

How do I see which authentication scheme the proxy wants?

Run the request with curl -v and read the Proxy-Authenticate header in the 407 response. Proxy providers almost always use Basic. Corporate gateways may answer with NTLM or Negotiate, which need a client that supports those schemes.


Final Thoughts

A 407 stops being mysterious once you remember it comes from the proxy and nothing else. For HTTPS targets, it shows up as a failed CONNECT tunnel, so read the exception text instead of hunting for a status code. Put the credentials in the proxy URL, encode special characters, and check your public IP if you rely on whitelisting. A browser showing 407 with no proxy you configured is almost always carrying a leftover setting. Proxyon supports both username/password and IP whitelisting, so you can pick the method that matches how your code is deployed and only pay for what you use.

Get back to building.

We'll handle the proxies.