Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
HTTP 407 Proxy Authentication Required means a proxy between your client and the destination server is demanding credentials, or rejecting the credentials already supplied. The proxy—not usually the website—returns the response and identifies acceptable authentication methods in Proxy-Authenticate. Fix it by confirming the intended proxy, reading that challenge, supplying current credentials through Proxy-Authorization, and retrying with a client that supports the required scheme.
What an HTTP 407 response means
HTTP 407 is a client-error status generated by an intermediary proxy. RFC 9110 defines it as a proxy challenge to the authorization of a client. A typical response looks like this:
HTTP/1.1 407 Proxy Authentication Required
Proxy-Authenticate: Basic realm="Access to internal site"
The Proxy-Authenticate header tells the client which authentication scheme (or schemes) the proxy accepts. The client can then repeat the request with a new or replaced Proxy-Authorization header. The destination server may never receive the original request.
Free tools Windows power users keep installed
One-click scans. No signup required.
Proxy authentication is different from website login
A proxy controls the route from your browser or application to the internet or an internal service. Its credentials are sent in Proxy-Authorization. A website or API server challenges the client with 401 Unauthorized, using WWW-Authenticate and Authorization. These headers serve different hops and should not be interchanged.
#1 Best Overall
- 【WIRELESS MOBILE MINI TRAVEL ROUTER】 Convert a public network (wired or wireless) to a private Wi-Fi for secure surfing. Tethering. Powered by any laptop USB, power banks or 5V/2A DC adapters (sold separately). 39g (1.41 Oz) only, portable and pocket friendly. 2.4GHz ONLY
- 【OPEN SOURCE & PROGRAMMABLE】 OpenWrt pre-installed, USB disk extendable.
- 【LARGER STORAGE & EXTENDABILITY】 128MB RAM, 16MB Flash ROM, dual Ethernet ports, UART and GPIOs available for hardware DIY.
- 【OPENVPN CLIENT】 OpenVPN client pre-installed, compatible with 30+ VPN service providers.
- 【PACKAGE CONTENTS】 GL-MT300N-V2 (Mango) mini router (2-year Warranty), USB cable, Ethernet cable, User Manual. Please update to the latest firmware.
407 is not the same as 403
A 403 Forbidden response generally means the server understood the request and credentials but will not authorize access. RFC 9110 says that when a proxy accepts authentication but the account is not permitted to access the requested resource, 403 is generally more appropriate than issuing another 407 challenge. Changing a password will not fix an account or policy restriction.
Why you are seeing 407
- A corporate, school, VPN, container, or hosting proxy is configured intentionally but your client has no credentials.
- An old password, expired token, or cached credential is being sent.
- Environment variables such as
HTTP_PROXY,HTTPS_PROXY, orALL_PROXYroute traffic through an unexpected proxy. - The browser, library, or command-line tool does not support the scheme named by
Proxy-Authenticate. - The proxy account is disabled or is not authorized by network policy.
- A proxy setting was added by security software or malware without your knowledge.
There is no reliable general prevalence statistic for 407 errors. Treat the exact response headers and your local route as the evidence for diagnosis.
A reliable 407 troubleshooting procedure
-
Confirm the proxy path
Check the application’s proxy setting, operating-system network settings, browser policy, container configuration, and environment variables. Verify the hostname and port with the network administrator. Temporarily compare a request with the proxy disabled only when policy permits; do not bypass a required enterprise control.
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy. -
Capture the challenge
Inspect response headers and record every
Proxy-Authenticatevalue. The scheme—not just the 407 status—determines what your client must do. Keep the response body and proxy host available for your administrator.Rank #2
SaleUGREEN NAS DXP2800 2-Bay for Advanced Home Users, Remote Workers & Creators- 【Advanced Home Data & Media Hub】For advanced home users who need phone backup, file storage, and centralized data management. Centralize family photos, 4K videos, movies, computer backups, and personal files in one place while running multiple apps for home entertainment and everyday data management. Suitable for households with growing digital libraries and multiple NAS use cases.
- 【Built for Creators, Media Servers & Advanced Apps】Powered by the Intel N100 Quad-Core CPU, 8GB DDR5 RAM, 2.5GbE networking, and dual M.2 NVMe slots, DXP2800 handles large files and heavier workloads with ease. Run Docker, virtual machines, and media server applications compatible with Plex—ideal for content creators, tech enthusiasts, and advanced home users managing 4K videos, RAW photos, personal media libraries, and multiple NAS apps.
- 【Up to 80TB for Growing Digital Libraries】 Supports up to 80TB of storage using two HDD bays and two M.2 NVMe SSD slots for family photos, movies, RAW photos, 4K videos, work files, and device backups. AI photo management supports recognition of people, objects, scenes, and locations, album organization, and duplicate photo detection. HDDs and SSDs are not included.
- 【AI-powered Home Surveillance】Turn DXP2800 into a centralized home surveillance hub by connecting compatible network cameras and storing recordings locally on your NAS. AI-powered features include Face Recognition, People Detection, and Pet Detection, helping advanced home users review important events more efficiently while managing home surveillance and personal data in one place.
- 【One data Center Across Your Devices】Keep files from desktops, laptops, phones, tablets, and other devices together instead of scattered across cloud accounts and external drives. Access, back up, organize, and share data across Windows, macOS, Android, iOS, web browsers, and compatible smart TVs—ideal for creators and advanced home users working across multiple devices.
-
Obtain the right identity
Ask the proxy administrator whether the required value is a username and password, token, certificate, or enterprise sign-in. A website password is not automatically a proxy password. Confirm account scope and whether the account is allowed to reach the requested destination.
-
Replace stale credentials and retry
Clear the client’s cached proxy credentials or restart the process after changing them. Retry with a newly generated
Proxy-Authorizationvalue. Never paste credentials into a URL that may be logged. -
Verify client and policy support
If valid credentials still produce 407, check whether the client implements the challenged scheme and whether the proxy requires a browser-based or certificate-based flow. An unsupported challenge cannot be repaired by repeatedly sending Basic credentials; involve the network administrator.
Windows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallCrashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteSpecial offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Fixing 407 in common clients
Chrome and Chromium-based browsers
- Open the operating system’s network or proxy settings from the browser’s settings page. Chrome normally inherits the system proxy on Windows, macOS, and Linux.
- Confirm the configured server, port, automatic-configuration URL, and bypass list. Remove an unexpected entry only if you control the device and policy allows it.
- Retry the URL and enter the proxy credentials when prompted. If no prompt appears, a managed policy, cached credential, or unsupported authentication scheme may be responsible.
- On a managed computer, provide the 407 response and
Proxy-Authenticateheader to IT rather than installing an extension that claims to bypass the proxy.
Use HTTPS for the destination whenever possible. Basic authentication is only base64-encoded, not encrypted; it is unsafe on an unprotected connection. TLS protects the exchange in transit, but still use the strongest scheme supported by your environment.
Rank #3
- One Place for All Your Data - Consolidate scattered files from multiple computers, phones and external drives into one accessible hub with 100% ownership
- Professional File Collaboration - Share projects with clients, sync documents across teams and maintain version control without Dropbox fees
- Automated Backup Protection - Set-and-forget backups for Macs, PCs and mobile devices to multiple destinations including cloud and external drives
- DIY Surveillance System - Transform IP cameras into a professional monitoring solution with motion alerts, recording schedules and remote viewing
- 2-Year Warranty - Reliable hardware backed by Synology's expert customer support team and ongoing software updates
curl
First expose headers without printing a password:
curl -I -v https://example.com
For a proxy that explicitly requires Basic credentials, provide them separately and let curl construct the header:
curl --proxy http://proxy.example:8080
--proxy-user 'USERNAME:PASSWORD'
https://example.com
Use an environment variable or a protected netrc file instead of placing secrets in shell history. If the proxy advertises another scheme, consult your curl version’s authentication support and your administrator’s policy; forcing Basic will not satisfy a proxy that requires a different method.
Python requests
Pass the proxy and credentials through the client’s proxy URL only in a controlled environment, and prefer a secret manager for production:
import requests
proxies = {
"http": "http://USERNAME:[email protected]:8080",
"https": "http://USERNAME:[email protected]:8080",
}
response = requests.get("https://example.com", proxies=proxies, timeout=30)
response.raise_for_status()
For special authentication schemes, use the library or adapter documented by your proxy vendor rather than assuming a URL username and password are sufficient. Check response.headers.get("Proxy-Authenticate") while diagnosing, but do not log authorization values.
Rank #4
- Unlimited bandwidth, unlimited data.
- Super-fast VPN and one tap connect.
- Free worldwide multiple servers.
- Works with all type of data carries. (Wi-Fi, 4G, LTE, 3G).
- No registration, sign up needed.
Node.js
Node’s built-in fetch does not automatically perform every proxy-authentication flow. Use the proxy agent recommended for your Node version and proxy scheme, and supply credentials through a secret store or environment variable. If the agent cannot implement the challenge, select a supported client or ask the administrator for a compatible method. Avoid embedding credentials in source code or URLs committed to a repository.
How to distinguish 407, 401, and 403 quickly
| Status | Challenger | Challenge/request headers | What to fix |
|---|---|---|---|
| 407 Proxy Authentication Required | Intermediary proxy | Proxy-Authenticate and Proxy-Authorization |
Proxy route, scheme, credentials, client support, or proxy policy |
| 401 Unauthorized | Origin server | WWW-Authenticate and Authorization |
Website or API authentication |
| 403 Forbidden | Usually origin server (or an authorized intermediary) | No new authentication challenge is required | Permissions, account scope, IP policy, or resource rules |
Security precautions
- Prefer HTTPS/TLS from client to destination and use the strongest proxy scheme your organization supports.
- Remember that Basic authentication is encoding, not encryption. Base64 can be decoded by anyone who obtains it.
- Do not send proxy credentials to the destination server’s
Authorizationheader. - Redact
Proxy-Authorization, passwords, tokens, and cookies from logs, support tickets, and packet captures. - Validate unexpected proxy changes with your administrator; an unknown proxy can observe or alter traffic.
- Use short-lived tokens and rotate credentials after accidental exposure.
Common failure symptoms and targeted fixes
| Symptom | Likely cause | Next action |
|---|---|---|
| 407 appears for every site | Missing or wrong global proxy credentials | Check system settings and proxy environment variables, then authenticate to the configured proxy. |
| Only one application fails | That client does not inherit credentials or support the challenge | Configure its proxy explicitly and verify its authentication capabilities. |
| It worked until a password change | Cached or expired credentials | Replace the stored secret and restart the client. |
| Browser prompts, script does not | Browser supports the enterprise flow; script does not | Use a supported library or obtain an automation credential approved by IT. |
| Correct credentials still return 407 | Wrong scheme, disabled account, or policy rejection | Compare the challenge with client support and ask the proxy administrator to check logs. |
| 407 follows a network change | New VPN, container, PAC file, or security product inserted a proxy | Trace the route and inspect automatic configuration and environment variables. |
Performance and reliability considerations
Proxy authentication adds at least one challenge-and-retry exchange. Reusing a connection after successful authentication can reduce repeated handshakes, while short-lived processes may pay the cost on every request. Configure sensible connection and request timeouts, retry only transient failures, and do not blindly retry a 407 with the same secret: repeated attempts can trigger account lockout. Monitor status codes and redact headers in telemetry. A cache, load balancer, or service mesh may generate its own proxy challenge, so identify the hop that actually returned the header before changing application code.
Or skip the browser setup
If your goal is simply to obtain a clean website image while diagnosing a page or proxy-visible route, ScreenshotNeo provides a website screenshot API and MCP server. Its capture endpoint can be called directly; see the ScreenshotNeo documentation for options and authentication.
The Tool Desk
Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp
import requests
r = requests.get("https://api.screenshotneo.com/v1/shot", params={"access_key": "YOUR_API_KEY", "url": "https://stripe.com"}, timeout=90)
open("shot.webp", "wb").write(r.content)
const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://stripe.com' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);
Before capture, ScreenshotNeo accepts cookie or consent banners and removes more than 60 known consent platforms, newsletter popups, and chat widgets; each step can be disabled. Bot checks or CAPTCHAs, blank pages, timeouts, failed loads, and cache hits are not billed, and response headers report the page verdict and billing status. Its MCP server includes take_screenshot, get_page_info, and capture_pdf for Claude, Cursor, and other MCP clients. The Free plan includes 1,000 screenshots per month with no card; paid plans start at $5 for 3,000 shots. Sign up free.
Frequently Asked Questions
Can a 407 come from the website itself?
A standard 407 is defined as a challenge from a proxy intermediary. A website can sit behind a proxy, but the response headers identify the hop requesting authentication.
Best Value
- Complete Phone & Computer Backup - Automatically protect photos, documents and videos from iPhone android, Mac and Windows to one secure location
- Your Private File Cloud - Access files from anywhere and share large projects with family or clients without relying on expensive cloud subscriptions
- Smart Home Security Hub - Monitor your home 24/7 with AI-powered surveillance that detects people, vehicles and sends instant alerts
- 100% Data Ownership - Keep full control of your personal data with multi-platform access and no monthly subscription fees
- 2-Year Warranty - Reliable hardware backed by Synology's expert customer support team and ongoing software updates
Should I keep retrying after a 407?
Retry once with newly supplied, correctly scoped credentials. Repeating the same failed secret can waste time or trigger account lockout; escalate when the scheme or policy is unclear.
Does disabling the proxy always solve the error?
Only when the proxy is unnecessary and bypassing it is permitted. On managed networks, disabling it may violate policy or remove required access.
Recommended Free Tools
The Bottom Line
Fix 407 at the proxy boundary: verify the route, read Proxy-Authenticate, provide an authorized credential in Proxy-Authorization, and use a client that supports the named scheme. If the account is authenticated but lacks permission, investigate a 403-style policy issue instead.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

