Proxy Login, Password, Port and Whitelist: Step-by-Step Access Setup for Beginners
Table of contents
- Introduction: what you'll get after reading
- Preparation: tools and access
- Basic concepts: what makes up proxy access
- Step 1: find your credentials in the dashboard
- Step 2: understanding ports and choosing a connection protocol
- Step 3: setting up login and password authorization
- Step 4: enabling whitelist ip authorization
- Step 5: testing the connection and reading server responses
- Step 6: changing credentials and storing them securely
- Result check: readiness checklist
- Common mistakes and their solutions
- Additional capabilities for advanced users
- Faq: common questions about access setup
- Conclusion
Introduction: What You'll Get After Reading
Everyone buying a mobile proxy for the first time runs into the same moment. A string of four parts appears in their dashboard: address, port, login, and password. Next to it there's some tab called "Whitelist" or "IP Access". And the obvious question pops up: what do I do with all this and where exactly do I enter it?
This guide fills exactly that gap. We won't compare proxy types or explain how mobile differs from residential—there are separate articles on the blog for that. Here we're only talking about the mechanics of access: what credentials look like, what each element means, how to correctly enter your login and password for a SOCKS5 or HTTP proxy, when it makes more sense to switch to whitelist authorization, and how to confirm everything works.
What you'll end up with:
- An understanding of what makes up a proxy access string and why the same proxy can have two different ports.
- A working connection via login and password in your browser, system settings, and command line.
- Whitelist IP authorization configured for cases where entering a password is impossible or inconvenient.
- The skill to quickly diagnose issues: you'll distinguish an authentication error from a port error in thirty seconds.
- Clear rules for storing and sharing credentials with your team without risking a leak.
Who this guide is for. Primarily marketers, media buyers, and business owners who work with mobile proxies but don't consider themselves technical specialists. Developers will find it useful too: a separate section covers inserting credentials into code, environment variables, and combined authorization schemes.
What you need to know beforehand. Practically nothing. It's enough to be able to open your browser settings, copy text, and type commands into a terminal following an example. We explain all terms as we go.
How much time it takes. The first read-through and setup of one connection will take 30–40 minutes. If you're configuring both password authorization and whitelist, allow about an hour. Reconfiguring after that takes two or three minutes.
Preparation: Tools and Access
Before jumping into the steps, gather everything you need. This saves time and avoids the situation where you're halfway through setup and discover you don't have access to your email or the right tool isn't installed.
What to Have on Hand
- An active proxy. A purchased or rented plan in your service dashboard. A trial works too—what matters is that the proxy has an "active" status.
- Access to your dashboard. The login and password for your account on the provider's site. Don't confuse these with the proxy's own credentials—they're different things, and we'll cover this in detail below.
- A browser. Any modern one: Chrome, Firefox, Edge. Preferably with the ability to install extensions.
- A terminal or command line. On Windows that's PowerShell or Command Prompt, on macOS and Linux the Terminal app. You'll need it for testing with curl.
- A text file or password manager to record credentials. Don't store them in an open messenger chat.
System Requirements
There are no special requirements. Any computer with Windows 10 or newer, macOS, or Linux will do. curl is already built into Windows 10 and later, macOS, and most Linux distributions—no separate installation needed. For mobile devices, it helps to know where the Wi-Fi settings are: on iOS and Android, the proxy is configured right there.
What to Install and Set Up in Advance
- Make sure your email is confirmed in the dashboard. When you change your proxy password, some services send a notification there.
- If you're planning whitelist authorization, find out your external IP address in advance. Open any IP-checking service in your browser, like ipify or whatismyipaddress, and note down the numbers. We'll show you how to do this in the terminal in step three.
- If you work through an antidetect browser or parser, open its proxy settings so you can see what fields it has. Usually it's "Type", "Host", "Port", "Login", "Password".
Backing Up Your Settings
Backing up here is simple: before any changes, save your current proxy access string somewhere safe. If something stops working after a password change or whitelist cleanup, you can compare old and new values and quickly figure out what changed. This is especially important if the proxy is already configured in a dozen antidetect browser profiles.
Tip: Set up a separate table with columns for "Proxy name", "Host", "HTTP port", "SOCKS5 port", "Login", "Password", "Whitelist IP", "Where used". After a month of working with multiple proxies, this table will save you hours.
Basic Concepts: What Makes Up Proxy Access
The topic seems simple, but this is exactly where most mistakes happen. Let's break down each element separately in plain language.
Host, or Server Address
The host shows exactly where your browser or program connects. It's either a domain name like proxy.example.net or an IP address like 185.10.20.30. The host doesn't match the IP that websites see. With a mobile proxy, the external address belongs to the cellular carrier and can change during rotation, while the host stays constant. That's why you enter the host in your settings, not the "IP from the checker".
Port
A port is like a door number in a large building. The building is one, but there are many doors, and each leads to its own service. A port is written as a number from 1 to 65535 and specified after the host with a colon. A proxy typically has two different ports: one for the HTTP or HTTPS protocol, another for SOCKS5. The same proxy on different ports responds in different "languages". If you send an HTTP request to the SOCKS5 door, the server just won't understand you, and the connection will drop.
Login and Password
This is the first of two ways to prove to the proxy that you have the right to use it. The login and password are generated by the provider when the proxy is issued and have nothing to do with your account on the website. Remember a simple rule: your dashboard password opens the provider's site, while the proxy login and password open the proxy itself. These are the ones people confuse most often.
An important nuance: the login and password for a SOCKS5 proxy and for the HTTP port are usually the same. Only the port and connection type change, while the credentials stay the same. That's convenient: one pair can be used across different programs.
Whitelist, or IP Allowlist
The second authorization method. Instead of entering a password, you tell the proxy server: "Let through any connections from my IP address without questions." The server records your address in the allowed list, and from then on you connect by specifying only the host and port. No login or password needed.
Where this helps: in programs that simply don't have fields for login and password, in Wi-Fi settings on your phone, in some older utilities, in CLI tools where you don't want to expose your password in command history. Where it gets in the way: if you have a dynamic home IP that changes after a router reboot, you'll have to update the whitelist regularly.
Access String Format
Providers issue credentials in one of several formats. Learn to recognize them at a glance:
- host:port:login:password, for example proxy.example.net:1050:user123:Qw8rT2pL. The most common format in dashboards.
- login:password@host:port, for example user123:Qw8rT2pL@proxy.example.net:1050. Parsers and antidetect browsers love this format.
- URL format with a scheme, for example socks5://user123:Qw8rT2pL@proxy.example.net:1050 or http://user123:Qw8rT2pL@proxy.example.net:8080. Used in the command line, in code, and in environment variables.
All three entries describe the same access. Your job when configuring any program is to break the string into four parts and place them into the right fields.
Tip: If your password contains the characters @, :, or /, in URL format they break the parsing. The program will think the password ended too early. In that case, either regenerate the password in your dashboard or encode the special characters: @ becomes %40, : becomes %3A, / becomes %2F.
Step 1: Find Your Credentials in the Dashboard
Goal of this stage: get the full set of connection data and confirm the proxy is active.
Provider interfaces differ, but the logic is similar everywhere. Let's describe a typical path using a mobile proxy service dashboard as an example.
- Log in to the provider's website. Enter your account email and password. If two-factor protection is enabled, confirm the login with a code.
- Open the section with your proxies. It's usually called "My Proxies", "Proxy List", or "Equipment". Find the corresponding item in the top menu or side panel.
- Find the proxy you need in the list. The status is displayed next to each one. You want a green indicator or the word "Active". If the proxy is in "Pending payment" or "Disabled" status, resolve the payment issue first.
- Click on the proxy row or the "Details", "Settings", or gear icon button. A card with details will open.
- In the card, find the connection data block. You'll see fields: Host or Server, HTTP Port, SOCKS5 Port, Login, Password. The password may be hidden with dots—there's usually an eye icon to reveal it.
- Copy each value separately using the copy button next to the field. If there's no button, select the value with your mouse and press Ctrl+C. Paste it into your prepared table.
- Pay attention to additional tabs in the card: "Whitelist", "IP Authorization", "Change IP", "Rotation Link". For now, just note where they are—you'll need them in step four.
Warning: Copy the password only using the copy button or by selecting strictly from the first to the last character. The most common cause of authentication errors is a trailing space captured during selection. Programs don't show this space, but the server sees it and rejects the request.
Tip: Many dashboards offer a "Copy in format" button with options like host:port:login:password or login:password@host:port. Use it if you plan to bulk-load proxies into an antidetect browser—it accepts exactly these string formats.
What to Do If the Password Looks Strange
Sometimes a password consists of thirty characters with hyphens, sometimes eight Latin letters. Both are normal. If the password contains characters you can't visually distinguish, like a capital I and a lowercase l, or a zero and the letter O, never retype it manually. Copy only.
Check: Your table has five fields filled in: host, HTTP port, SOCKS5 port, login, password. The proxy status in the dashboard is "Active". If a port is missing, read your plan description: some packages only provide one protocol.
Possible Problems at This Stage
- No show-password button. Look for a "Change password" or "Generate new" link. After generating, the password will be shown in plain text once—save it immediately.
- Only one port listed. Some providers use one port for both protocols with auto-detection. In that case, you enter the same number for both SOCKS5 and HTTP; only the connection type differs in your program settings.
- The host is listed as an IP but the documentation shows a domain. These are equivalent options. The domain is more convenient: if the server moves to another IP, you won't have to change anything.
Step 2: Understanding Ports and Choosing a Connection Protocol
Goal of this stage: correctly match the port with the connection type so your program and proxy "speak the same language".
This is the most underrated step. Your login and password may be perfectly correct, but with the wrong port-protocol pair you'll get a timeout and waste time changing your password over and over. Let's cover how to avoid this trap.
How to Tell Which Port Is for What
- Look at the proxy card. Ports are usually explicitly labeled: "HTTP: 8080", "SOCKS5: 1080". The numbers differ per provider—go by the labels, not specific values.
- If there are no labels, check the provider's documentation or the tooltip next to the field. There's often a line like "For HTTP use the port in the first field, for SOCKS5 the second".
- Determine which connection type your program supports. In your browser or antidetect settings there's a dropdown for "Proxy type": HTTP, HTTPS, SOCKS4, SOCKS5. Note what you selected there.
- Match them up: if you selected SOCKS5 in the program, enter the SOCKS5 port. If you selected HTTP or HTTPS, enter the HTTP port. The login and password are the same for both.
Breaking Down the String Into Parts
Let's take a sample string in host:port:login:password format:
mp.example.net:1050:u48213:kR7pZq2mWx
Read from left to right. Everything before the first colon is the host: mp.example.net. The number after it is the port: 1050. Then the login: u48213. The last part is the password: kR7pZq2mWx. If the dashboard states that 1050 is the SOCKS5 port, this string is meant for programs with the SOCKS5 connection type.
Now the same string in URL format for SOCKS5:
socks5://u48213:kR7pZq2mWx@mp.example.net:1050
Notice the different order: first the scheme, then the login and password separated by a colon, then the @ symbol, then the host and port. For an HTTP port, say 8080, the string will start with the http scheme and end with a different number, while the login and password stay the same.
Tip: If your program offers HTTP and HTTPS as proxy type options, they're almost always the same thing: a connection to the proxy's HTTP port, through which you can open both regular and secure sites. Choose HTTP and enter the HTTP port. A separate HTTPS port doesn't exist with most providers.
How to Tell You've Mixed Up the Ports
The signs are characteristic. When a SOCKS5 client hits an HTTP port, you'll get a connection drop or a message like "SOCKS handshake failed". When an HTTP client hits a SOCKS5 port, the typical response is an empty server reply, "Empty reply", or a timeout with no error code. But if you see code 407 Proxy Authentication Required, the port is correct and the problem is with your login or password. That's a handy marker: a 407 error means you reached the proxy.
Check: You can say without hints which port your proxy uses for SOCKS5 and which for HTTP, and you can write the access string in two formats for each of them.
Possible Problems
- The program only supports HTTP, but the plan only lists SOCKS5. Check whether the provider has an option to switch the port protocol in the proxy card. Often the protocol on a port can be changed with one click.
- The provider issued three ports. Usually the third one is for getting the IP change link or for statistics. Don't put it into the proxy settings.
Step 3: Setting Up Login and Password Authorization
Goal of this stage: get a working connection via password in three typical scenarios: a browser with an extension, system settings, and the command line.
Option A: Browser via Extension
Chrome and Edge don't have their own window for entering a proxy login and password in settings—they use the system proxy. That's why it's easiest to work through a switcher extension like Proxy SwitchyOmega or similar. Firefox can configure proxies on its own, but it will ask for the password in a pop-up window on the first request.
- Install a proxy management extension from your browser's official extension store.
- Open the extension settings. Click "New profile" or "Add proxy".
- In the "Protocol" field, select SOCKS5 if you're using the SOCKS5 port, or HTTP for the HTTP port.
- In the "Server" field, paste the host, for example mp.example.net.
- In the "Port" field, enter the number matching the selected protocol.
- Find the lock button or the "Authentication" item. Click it. Fields for "Username" and "Password" will appear. Paste the proxy login and password there.
- Save the profile with the "Apply" or "Save" button.
- Click the extension icon in the browser toolbar and select the profile you created. The icon will change color.
- Open any IP-checking service. You should see a mobile carrier address, not your home internet provider's.
Warning: Some extensions don't support sending login and password for SOCKS5 due to browser limitations, and authorization only works for the HTTP port. If selecting SOCKS5 causes the browser to endlessly prompt for a password or throw an error, switch to the HTTP port of the same proxy with the same credentials. The result for websites will be identical.
Option B: Windows System Settings
- Press the Windows key and open "Settings".
- Go to "Network & Internet", then "Proxy".
- In the "Manual proxy setup" block, toggle "Use a proxy server" to "On".
- In the "Address" field enter the host, in the "Port" field the HTTP port. The Windows system proxy works over HTTP.
- Click "Save".
- Open your browser and go to any website. A system window will appear asking for username and password. Enter the proxy login and password and check "Remember" if that option is available.
Note: the system proxy applies to all computer traffic, including updates and messengers. For targeted work with a single browser or profile, Option A is more convenient.
Option C: Command Line and curl
This method is the most honest for diagnostics: it shows the raw server response without any layers. Open your terminal and run the command, substituting your own data.
For the SOCKS5 port:
curl -x socks5://u48213:kR7pZq2mWx@mp.example.net:1050 https://api.ipify.orgFor the HTTP port:
curl -x http://u48213:kR7pZq2mWx@mp.example.net:8080 https://api.ipify.orgIf the password contains special characters, it's safer to pass the credentials as a separate parameter—then nothing needs encoding:
curl -x socks5://mp.example.net:1050 -U u48213:kR7pZq2mWx https://api.ipify.orgA successful result is a single line with an IP address. Add the -v flag to see connection details: you'll see whether the host connection was established, whether authentication passed, and what code the server returned.
Tip: In PowerShell, the curl command without an extension may invoke a built-in cmdlet rather than the real utility. Write curl.exe instead of curl to avoid confusion.
Option D: Smartphone
On iOS and Android, the proxy is configured in the parameters of a specific Wi-Fi network. Open Wi-Fi settings, tap your network, find "Proxy" or "HTTP Proxy", select "Manual", enter the host and HTTP port. On iOS, "Authentication" fields with login and password will appear. On Android, login and password fields are often missing, so whitelist authorization is more convenient for phones—that's the next step. Mobile systems only work with the HTTP port; SOCKS5 isn't available in system settings.
Check: In at least one of the options, the IP-checking service shows an address different from your home one. The curl command returned an IP without error messages. Traffic for the last few minutes appeared in the proxy statistics in your provider dashboard.
Possible Problems
- Error 407. The login or password is incorrect. Copy them again from the dashboard, check for extra spaces, make sure you didn't paste your dashboard password.
- The browser asks for the password again and again. Often the cause is cached incorrect data. Clear saved passwords for this host or recreate the profile in the extension.
- Works in curl, doesn't work in the browser. That means the credentials are correct and the problem is in the browser settings. Check the protocol type and port in the extension.
Step 4: Enabling Whitelist IP Authorization
Goal of this stage: set up proxy access without entering a password, using only your IP address, and understand when this method makes sense.
When to Choose Whitelist
The allowlist helps in four situations. First: the program can't pass login and password, like Android in Wi-Fi settings. Second: you have a static IP on a server or in the office, and entering a password across a dozen services is inconvenient. Third: you don't want the password stored in scripts and logs. Fourth: several employees use the proxy from one office address, and adding the IP once is easier than distributing the password.
There's a flip side too. If your external IP changes—and with home providers that's normal—the proxy will stop letting you in after every address change. Also, anyone who happens to be on your network will get proxy access without a password. Weigh this before enabling it.
Determining Your External IP
- Make sure the proxy in your browser is currently off. Otherwise you'll see the proxy's IP, not your own.
- Open an IP-checking service in your browser or run a command in the terminal without a proxy: curl https://api.ipify.org.
- Note the address. It's four numbers separated by dots, for example 93.184.216.34. If the service shows a long address with colons, that's IPv6. Most proxy services only accept IPv4 in the whitelist, so use a service that shows IPv4 specifically.
- If you're setting up access for a remote server, run the same curl command on it. Your home IP won't be accepted by the server.
Adding an IP to the Allowlist
- Go back to the provider dashboard and open the card for the proxy you need.
- Go to the "Whitelist", "IP Authorization", or "IP Access" tab. The name depends on the service.
- You'll see an input field and possibly a list of already added addresses. Paste your IP into the field.
- Click "Add" or "Save". The address will appear in the list. Some dashboards let you add multiple addresses, one per line, or specify a subnet.
- Pay attention to the authorization mode switch, if there is one: "Login and password only", "IP only", "Login and password or IP". For flexibility, choose the combined mode: the password keeps working for those whose IP isn't on the list, while you log in without a password.
- Wait one or two minutes. With many services, changes don't apply instantly.
Warning: Never add someone else's or temporary addresses to the whitelist, like an IP from hotel Wi-Fi or a coworking space. Everyone behind that same router gets your proxy for free, and the traffic costs and possible consequences fall on you. After working from a temporary network, remove its address from the list.
Connecting Without a Password
Now in any program specify only the host and port, and leave the login and password fields empty. In curl it looks like this:
curl -x socks5://mp.example.net:1050 https://api.ipify.orgIf you got a response, the whitelist works. In Wi-Fi settings on Android, enter the host and HTTP port, don't touch the credential fields, save, and open a website.
Tip: If your home IP changes and you really need the whitelist, ask your internet provider about a static address service. It's usually inexpensive and eliminates the problem entirely. An alternative for developers: a script that compares the current IP with the saved one every few minutes and updates the whitelist via the proxy service's API when it changes.
Check: The curl command without login and password returns a mobile carrier IP. The whitelist contains exactly the addresses you intentionally added. Trying to connect from another device on a different network without a password is rejected—this confirms the list actually filters.
Possible Problems
- Added the IP, still no access. Check that you added IPv4, not IPv6, that enough time has passed, and that the authorization mode isn't set to "Login and password only".
- Worked in the morning, stopped in the evening. Almost certainly your external IP changed. Compare the current address with the one you recorded.
- The dashboard won't accept the address. Make sure there are no spaces and that you didn't paste a string like "IP: 93.184.216.34" along with the label.
Step 5: Testing the Connection and Reading Server Responses
Goal of this stage: learn to determine in a minute whether access works and understand from the response exactly what broke.
Three-Level Check
- Host reachability check. Run curl -v -x http://mp.example.net:8080 https://api.ipify.org without credentials. If the verbose output has a line "Connected to mp.example.net", the network path to the proxy is open. If "Could not resolve host", the host is misspelled. If "Connection refused" or "Connection timed out", the port is wrong or the proxy is unreachable.
- Authentication check. Same command, but with login and password. A 407 response in the verbose output means incorrect credentials. A 200 response and an IP at the end means success. For whitelist, repeat the command without credentials: the result should be the same.
- Check the result for websites. Open an IP-checking service and look not only at the address but also at the carrier name. It should match a mobile carrier, not your home provider.
Reading Typical Responses
- 200 OK and an IP in the response: everything works.
- 407 Proxy Authentication Required: port and host are correct, the error is in the login or password, or the IP isn't in the whitelist in "IP only" mode.
- 403 Forbidden: the proxy rejected the request by policy. This is often how "IP only" mode reacts to someone else's address, or a proxy with an expired term.
- Connection timed out: wrong port, outbound connection blocked by your firewall, or inactive proxy.
- SOCKS5 handshake failed: you're hitting an HTTP port with a SOCKS5 client.
- Empty reply from server: an HTTP client is hitting a SOCKS5 port.
Tip: Save two working curl commands in a note—one for the SOCKS5 port, another for HTTP. When something stops working in your antidetect browser or parser, run them first. If curl responds normally, the problem is in the program, not the credentials, and you'll immediately narrow down the search.
Check: You got a 200 response with an IP using at least one authorization method and understand which error code corresponds to a wrong password and which to a wrong port.
Possible Problems
- curl responds, the browser doesn't. Another extension managing the proxy is enabled in the browser, or the system proxy conflicts with the extension. Disable everything extra.
- Carrier IP shows, but the site loads slowly. That's no longer about authorization but channel quality—a topic for a separate article.
Step 6: Changing Credentials and Storing Them Securely
Goal of this stage: establish hygiene for working with passwords and whitelist so your proxy doesn't leak and you don't have to reconfigure everything in a rush.
When to Change the Proxy Password
Change the password if it ended up in a group chat, if a contractor who knew it left the project, if traffic appeared in the proxy statistics during hours when you weren't working, and simply on a schedule once every one or two months. Changing a password takes a minute, but recovering from a leak takes hours.
How to Change the Password
- Open the proxy card in your dashboard.
- Find the "Change password", "Generate new", or refresh icon button next to the password field.
- Click it. Some services will ask you to confirm the action. The new password will appear in the field.
- Copy it into your table immediately. The old password stops working within a minute.
- Update the password everywhere it's used: browser extension, antidetect profiles, scripts, phone settings. This is where the "Where used" column from your table comes in handy.
- Run the check from step five with the new password.
Warning: If the proxy is configured in dozens of antidetect browser profiles, changing the password will require a bulk update. Before changing it, make sure your browser has a bulk proxy editing feature, otherwise you'll have to fix profiles one by one. In some cases it's more convenient to temporarily move profiles to whitelist using the server's IP where the antidetect runs, and only then change the password.
How to Safely Share Access With a Colleague
- Use a password manager with shared folders. The colleague gets access without sending the string through a messenger.
- If there's no manager, send the host and port through one channel and the password through another, for example email and voice.
- For contractors, consider whitelist: add their server's IP, and the password never leaves your team. When the work is done, just remove the address from the list.
- Never post the access string in screenshots, support tickets, or public repositories.
How to Roll Back Changes
If something broke after a password change or whitelist cleanup, rolling back is simple. Compare the current values with the backup from the preparation stage. Put the IP back in the whitelist if you deleted too much. The password can't be reverted, but the new one is already in your table: double-check that it was copied without spaces and update it in the problematic program.
Check: The new password works in curl and in all the programs on your list. The old password returns 407. There are no outdated entries in your credentials table, and the whitelist contains only current addresses.
Result Check: Readiness Checklist
Go through the list. If every item is checked off, access setup is fully complete.
- You know your proxy's host and can distinguish it from the external IP that websites see.
- You've recorded both ports and understand which one is for SOCKS5 and which for HTTP.
- The login and password for the SOCKS5 and HTTP proxy are recorded in your table and match each other.
- The curl command with credentials returns a mobile carrier IP.
- At least one working program, browser, or antidetect connects through the password.
- If you need a whitelist, your IPv4 is added, and the passwordless connection works.
- You know what responses 407, 403, timeout, and SOCKS handshake error mean.
- Credentials are stored in a password manager or a secure table, not in a chat.
- You have a list of places where the proxy is used for quick password updates.
How to Test End-to-End
- Turn off the proxy everywhere and check your regular IP.
- Turn on the proxy via password in the browser and check the IP: it should change.
- Turn off the password in the settings, leaving the host and port, and check: if the whitelist is configured, the IP will stay as the proxy address; if not, an error will appear.
- Run both curl commands and make sure the response is the same.
- Open the proxy statistics in your dashboard: your traffic for the last few minutes should be there.
Success indicators: three out of three IP checks gave the expected result, no command returned 407, the dashboard statistics updated.
Common Mistakes and Their Solutions
We've collected the problems almost every beginner runs into. Format: problem, cause, solution.
Error 407 With Seemingly Correct Data
Cause: an extra space, the dashboard password instead of the proxy password, an outdated password after a change, an invisible character when copying from a PDF or chat.
Solution: open the proxy card, copy the login and password again using the copy buttons, paste into Notepad, and make sure the length matches what you expect. Test via curl with the -U parameter.
Timeout With No Error Code
Cause: wrong port for the selected protocol, proxy inactive, outbound connection to this port blocked by a corporate firewall.
Solution: verify the port against the label in the dashboard, check the proxy status, try the second port of the same proxy. If it doesn't work from the office but works from your phone via mobile internet, the issue is office network restrictions—contact your administrator.
Whitelist Added but No Access
Cause: IPv6 added instead of IPv4, the address changed, the authorization mode is set to "Login and password only", the changes haven't applied yet.
Solution: verify the current IPv4 against the entry in the list, check the mode, wait two minutes, and try again.
Browser Endlessly Asks for the SOCKS5 Password
Cause: a browser or extension limitation on passing credentials in SOCKS5.
Solution: switch the profile to the HTTP port with the same login and password, or use the whitelist for SOCKS5.
@ or : Characters in the Password Break the String
Cause: URL format treats these characters as separators.
Solution: encode the characters (%40 for @, %3A for colon) or regenerate the password in your dashboard to get a simpler character set. In curl, pass the credentials via -U, where no encoding is needed.
Proxy Works on One Computer and Not Another
Cause: the first computer's IP is in the whitelist and the second's isn't, with the authorization mode set to "IP only". Or the second computer has an old password.
Solution: check the authorization mode and the currency of data on the second device. The combined "password or IP" mode resolves most of these situations.
Changed the Password, but Some Programs Still Work With the Old One
Cause: some proxy servers keep already established connections open—the break only happens on reconnect.
Solution: this isn't an error. Update the password in all programs now so they don't drop at an inconvenient moment after reconnecting.
After Pasting a List String, the Antidetect Mixed Up Login and Port
Cause: the program expects a different field order, for example login:password@host:port, but you pasted host:port:login:password.
Solution: look at the format example in the program's import window and bring your string in line with it. The provider dashboard often offers a format choice when copying.
Additional Capabilities for Advanced Users
This section is for developers and those automating work with proxies. If you're just starting out, you can come back to it later.
Credentials in Environment Variables
Many tools, including curl, pip, git, and most HTTP libraries, read proxies from the HTTP_PROXY, HTTPS_PROXY, and ALL_PROXY environment variables. This lets you avoid specifying the password in every command. Example for Linux and macOS:
export ALL_PROXY=socks5://u48213:kR7pZq2mWx@mp.example.net:1050After that, a curl command without the -x flag will go through the proxy. In PowerShell, the equivalent: $env:ALL_PROXY = "socks5://u48213:kR7pZq2mWx@mp.example.net:1050". Remember that the variable lives only in the current terminal session, and when using a whitelist you can remove the credentials from the string.
Inserting Into Python Code
The requests library with the SOCKS add-on installed accepts a proxy dictionary. The login and password for the SOCKS5 proxy are specified right in the URL. The socks5h scheme means DNS queries also go through the proxy, which is usually what you want:
proxies = {"http": "socks5h://u48213:kR7pZq2mWx@mp.example.net:1050", "https": "socks5h://u48213:kR7pZq2mWx@mp.example.net:1050"}Best practice: don't store the password in code—read it from an environment variable or a secrets file that doesn't end up in version control.
Auto-Updating the Whitelist via API
If the provider offers an API, you can write a small script: every five minutes it requests the current external IP, compares it with the saved one, and sends an update request for the allowlist if they differ. This way you get the benefits of a whitelist even with a dynamic home IP. Note that the API key is a third type of credential, and it should be protected just as strictly as the proxy password.
Combined Authorization Scheme
The optimal scheme for a team looks like this. Permanent servers running a parser or antidetect are added to the whitelist and connect without a password. Employees on laptops use login and password. The authorization mode in the dashboard is set to "password or IP". The password changes on a schedule, and the IP list is reviewed with any infrastructure change. This scheme solves both the dynamic address problem and the password-in-scripts problem.
Different Credentials for Different Tasks
If the provider allows creating multiple login-password pairs for one proxy or multiple connections on different ports, use this for separation. One login for parsing, another for manual browser work, a third for a contractor. In case of a leak or the end of a collaboration, you revoke one pair without touching the others.
Logging Authorization Attempts
In the dashboard statistics you can usually see traffic volume and activity times. Check it once a week. A spike in traffic at night or connections during hours when the team isn't working is an early sign that credentials have gone to the wrong hands. The standard response: change the password and review the whitelist.
FAQ: Common Questions About Access Setup
Are the login and password for SOCKS5 and HTTP proxies the same credentials?
Yes, with the vast majority of providers one credential pair works on both ports. Only the port and connection type change in the program. If you have two different pairs, it will be explicitly stated in the proxy card.
How does the proxy password differ from the dashboard password?
The dashboard password protects your account on the provider's site: payment, proxy list, settings. The proxy password is checked by the proxy server itself on every connection. These are independent credentials. Inserting the dashboard password into proxy settings always gives error 407.
Can I use whitelist and password at the same time?
Yes, if the dashboard has a combined mode. Then connections from addresses on the list go through without a password, while all others must present login and password. This is the most flexible option for a team.
How often should I change the proxy password?
A reasonable guideline is once every one or two months and immediately upon any suspicion of a leak or when a person who knew the password leaves. The change takes a minute—the main thing is to update the password in all programs right away.
Why does the proxy work in curl but not in the browser?
The credentials are correct, and the problem is in the browser settings: wrong protocol type, a conflict between two extensions, or a system proxy enabled on top of the extension. Disable everything extra and recreate the profile in the extension.
The whitelist stops working after a router reboot. What should I do?
You have a dynamic IP. Options: order a static address from your internet provider, switch to password authorization, or set up a script to auto-update the whitelist via API. For home use, a password is usually simpler.
How do I know which port to use: SOCKS5 or HTTP?
Look at the "Proxy type" dropdown in your program. If you selected SOCKS5, enter the SOCKS5 port. If you selected HTTP or HTTPS, enter the HTTP port. If the program doesn't offer a choice, it usually expects HTTP.
What should I do if the password contains an @ character?
In host:port:login:password format it doesn't interfere. In URL format, replace it with %40. In curl, use the -U parameter, where encoding isn't needed. The simplest option is to regenerate the password if the dashboard allows it.
Is it safe to send proxy login and password in a messenger?
Not advisable. The string stays in chat history and in backups. Use a password manager with shared access, or a whitelist where the password doesn't need to be sent at all.
How do I check that no one is using my credentials without me?
Regularly check the traffic statistics in your dashboard. Activity outside working hours or an unexplained volume increase is a signal to change the password and review the whitelist.
Conclusion
Let's sum it up. You've learned what makes up proxy access: the host points to the server, the port selects the protocol, and the login with password or IP allowlist confirms your right to connect. You found your credentials in the dashboard, matched ports with connection types, set up password authorization in the browser, system, and terminal, enabled the whitelist where it makes sense, and learned to read server responses, distinguishing a password error from a port error. Separately, you established hygiene: a credentials table, regular password changes, and secure access sharing with your team.
What to do next. Enter the verified data into your working tools: antidetect browser, parser, ad services. If a tool accepts a proxy list, use the format from the dashboard so you don't have to parse strings manually. Set a reminder to change the password in a month.
Where to grow. The next logical level is automation: managing IP rotation via a link, updating the whitelist via API, storing secrets in environment variables and managers. There are separate blog articles on these topics. You now know the mechanics of access, which means any further configuration will rest on a solid foundation. Good luck working with proxies.