Geonode logo
Proxy and connection errors

How to Fix 407 Proxy Authentication Required

Three fixes, most common first, with copy-ready code for cURL, Python and Node.js.

Updated

TL;DR

A 407 Proxy Authentication Required comes from your proxy, not the website: the proxy wanted a valid login and stopped the request before passing it on. The fastest fix is to paste the proxy username and password from your provider's dashboard again, or whitelist your IP.

What error 407 looks like in each client

Browsers turn a 407 into a login prompt. Tools and libraries report a failed tunnel for https:// targets, because the proxy refused the CONNECT request that opens it.

WhereWhat you see
Chrome (Sign in dialog)The proxy http://proxy.geonode.io:9000 requires a username and password.
Firefox (login prompt)The proxy moz-proxy://proxy.geonode.io:9000 is requesting a username and password. The site says: “<text sent by the proxy>”
Raw response (curl -v, http:// target)HTTP/1.1 407 Proxy Authentication Required
curl, https:// targetCONNECT tunnel failed, response 407
Python requests and urllib3 (ProxyError)Tunnel connection failed: 407 Proxy Authentication Required
npm (error code E407)407 Proxy Authentication Required - GET https://registry.npmjs.org/express
.NET HttpClient (HttpRequestException)The proxy tunnel request to proxy 'http://proxy.geonode.io:9000/' failed with status code '407'

Why this happens

The proxy wants a login before it forwards anything, and yours was missing or wrong.

Your client sends it in a Proxy-Authorization header, separate from the website's own. A common cause is the Geonode account email and password typed where the proxy's API username and password belong.

Diagnose your 407 first

Each check splits one cause from the rest, so run them before you change any setting.

  • Read the status code; if it is 401 with WWW-Authenticate, the website wants its own login and the proxy already let you through.

  • Run curl -v through the proxy with --proxy-user 'USERNAME:PASSWORD'; if CONNECT gets a 200 reply, your app is not delivering the login.

  • Load one http:// and one https:// page through the same client; if only https:// fails, the login never reaches the CONNECT request.

  • Look at the Proxy-Authenticate header; if it names NTLM or Negotiate, the proxy wants your Windows account login.

  • Compare your public IP on a what-is-my-IP page with the dashboard whitelist; if they differ, whitelisting no longer covers you.

Solutions ranked by effectiveness

Try them in order and stop as soon as the 407 is gone.

  1. Most common fix

    Copy the login again and encode it

    Applies when the proxy gets a login and rejects it. Copy the API username and password from the Proxies section without spaces, and percent-encode @, :, /, # and % in a proxy URL.

    curl -x http://proxy.geonode.io:9000 \
      --proxy-user 'USERNAME:PASSWORD' \
      https://api.ipify.org
  2. Check next

    Whitelist your IP so no login is needed

    Applies when the app or device has nowhere to enter a proxy password. Geonode accepts traffic from an approved IP in place of a username and password.

    1. Open Whitelisted IPs in dashboard settings; type the public IP or click Detect My IP.

    2. Add a label such as Office if you like, then click Add.

    3. Remove the username and password from the app and keep the host and port.

  3. For developers

    Send the login on the CONNECT request

    Applies when your code sets Proxy-Authorization itself. Hand it to the proxy layer, which sends it with CONNECT; as an ordinary request header it travels inside the tunnel, out of the proxy's sight.

    AUTH=$(printf '%s' 'USERNAME:PASSWORD' | base64 | tr -d '\n')
    curl -x http://proxy.geonode.io:9000 \
      --proxy-header "Proxy-Authorization: Basic $AUTH" \
      https://api.ipify.org

Stop the 407 from coming back

A few habits keep a working login from breaking again after a password change or a move to a new network.

  1. Resetting the API password deactivates the old one, so update shell profiles, .npmrc, CI secrets and saved browser logins.

  2. Make scrapers stop at the first 407, because resending the same login only gets the same answer.

  3. Keep proxy passwords to plain ASCII, since Basic auth leaves the character encoding undefined and clients can send different bytes.

  4. Delete the Proxy-Authorization line before you share curl -v output, because its base64 decodes straight back to the password.

  5. Whitelist each network you work from before you need it; one user can keep up to 150 IPs.

Proxies that log in by IPWhitelist your IP once, and apps connect without a username or password.
Try residential proxies

Related errors

Learn more

FAQ

Run npm config set https-proxy with the full proxy URL, login included. npm falls back to the HTTPS_PROXY variable only when neither https-proxy nor proxy is set, so an old password left there brings E407 back.

Android's Wi-Fi proxy screen has only "Proxy hostname", "Proxy port" and "Bypass proxy for", with no login fields. Chrome shows its own login prompt; apps that cannot show one get a 407 until the phone's IP is whitelisted.

Chrome ignores logins saved in system proxy settings, such as the macOS "Proxy server requires password" fields, and asks in its own Sign in dialog. Type the login there or store it in the Geonode Proxy Manager extension.

Firefox asks through a moz-proxy:// prompt. Save the login there, then tick "Do not prompt for authentication if password is saved" in Connection Settings, and Firefox signs in to the proxy silently.

It is how older curl releases report a proxy that refused to open an https:// tunnel because the login was missing or wrong. Current curl prints "CONNECT tunnel failed, response 407" for the same failure.

Python's http.client raises this text, and requests wraps it in a ProxyError. Pass proxies= on each requests call, because HTTP_PROXY and HTTPS_PROXY override session.proxies and can carry an old password.

Every login detail in one line

The dashboard lists host, port, username and password together, ready to paste.