How to Fix 407 Proxy Authentication Required
Three fixes, most common first, with copy-ready code for cURL, Python and Node.js.
Updated
TL;DR
A 407 Proxy Authentication Required comes from your proxy, not the website: the proxy wanted a valid login and stopped the request before passing it on. The fastest fix is to paste the proxy username and password from your provider's dashboard again, or whitelist your IP.
What error 407 looks like in each client
Browsers turn a 407 into a login prompt. Tools and libraries report a failed tunnel for https:// targets, because the proxy refused the CONNECT request that opens it.
| Where | What you see |
|---|---|
| Chrome (Sign in dialog) | The proxy http://proxy.geonode.io:9000 requires a username and password. |
| Firefox (login prompt) | The proxy moz-proxy://proxy.geonode.io:9000 is requesting a username and password. The site says: “<text sent by the proxy>” |
| Raw response (curl -v, http:// target) | HTTP/1.1 407 Proxy Authentication Required |
| curl, https:// target | CONNECT tunnel failed, response 407 |
| Python requests and urllib3 (ProxyError) | Tunnel connection failed: 407 Proxy Authentication Required |
| npm (error code E407) | 407 Proxy Authentication Required - GET https://registry.npmjs.org/express |
| .NET HttpClient (HttpRequestException) | The proxy tunnel request to proxy 'http://proxy.geonode.io:9000/' failed with status code '407' |
Why this happens
The proxy wants a login before it forwards anything, and yours was missing or wrong.
Your client sends it in a Proxy-Authorization header, separate from the website's own. A common cause is the Geonode account email and password typed where the proxy's API username and password belong.
Diagnose your 407 first
Each check splits one cause from the rest, so run them before you change any setting.
Read the status code; if it is 401 with WWW-Authenticate, the website wants its own login and the proxy already let you through.
Run curl -v through the proxy with --proxy-user 'USERNAME:PASSWORD'; if CONNECT gets a 200 reply, your app is not delivering the login.
Load one http:// and one https:// page through the same client; if only https:// fails, the login never reaches the CONNECT request.
Look at the Proxy-Authenticate header; if it names NTLM or Negotiate, the proxy wants your Windows account login.
Compare your public IP on a what-is-my-IP page with the dashboard whitelist; if they differ, whitelisting no longer covers you.
Solutions ranked by effectiveness
Try them in order and stop as soon as the 407 is gone.
- Most common fix
Copy the login again and encode it
Applies when the proxy gets a login and rejects it. Copy the API username and password from the Proxies section without spaces, and percent-encode @, :, /, # and % in a proxy URL.
curl -x http://proxy.geonode.io:9000 \ --proxy-user 'USERNAME:PASSWORD' \ https://api.ipify.org - Check next
Whitelist your IP so no login is needed
Applies when the app or device has nowhere to enter a proxy password. Geonode accepts traffic from an approved IP in place of a username and password.
Open Whitelisted IPs in dashboard settings; type the public IP or click Detect My IP.
Add a label such as Office if you like, then click Add.
Remove the username and password from the app and keep the host and port.
- For developers
Send the login on the CONNECT request
Applies when your code sets Proxy-Authorization itself. Hand it to the proxy layer, which sends it with CONNECT; as an ordinary request header it travels inside the tunnel, out of the proxy's sight.
AUTH=$(printf '%s' 'USERNAME:PASSWORD' | base64 | tr -d '\n') curl -x http://proxy.geonode.io:9000 \ --proxy-header "Proxy-Authorization: Basic $AUTH" \ https://api.ipify.org
Stop the 407 from coming back
A few habits keep a working login from breaking again after a password change or a move to a new network.
Resetting the API password deactivates the old one, so update shell profiles, .npmrc, CI secrets and saved browser logins.
Make scrapers stop at the first 407, because resending the same login only gets the same answer.
Keep proxy passwords to plain ASCII, since Basic auth leaves the character encoding undefined and clients can send different bytes.
Delete the Proxy-Authorization line before you share curl -v output, because its base64 decodes straight back to the password.
Whitelist each network you work from before you need it; one user can keep up to 150 IPs.
Related errors
Learn more
FAQ
Every login detail in one line
The dashboard lists host, port, username and password together, ready to paste.


