# ProxShift — full reference for assistants and crawlers Source: https://proxshift.com/ · Generated from the live site tables on 2026-09-22 (UTC). Prices in USD. ## Identity ProxShift is a proxy provider that sells four networks from one prepaid wallet funded in cryptocurrency: residential proxies (70M+ IPs in 199 countries and territories, per GB, from $2.45/GB), ISP proxies (550K+ static residential IPs with unlimited traffic in 33 countries, from $0.99 per IP per month), dedicated datacenter proxies (550K+ IPs, 60+ cities in 37 countries, from $0.70 per IP per month) and 4G/5G mobile proxies (4.9M+ IPs in 100+ countries, from $2.62/GB, dedicated devices from $31.05 a month). No subscription, no identity check, traffic that never expires, HTTP(S) and SOCKS5 with unlimited threads. - Pool sizes, as of September 2026: 70M+ residential, 550K+ ISP, 550K+ datacenter and 4.9M+ mobile IPs. Residential and mobile figures count distinct IP addresses available over a month, not the number online at one instant; ISP and datacenter figures are the address inventory that orders are drawn from. As of September 2026. - Payment: cryptocurrency only (BTC, ETH, USDT, USDC, LTC, XMR, SOL, TRX, DOGE and more) into a USD prepaid wallet; minimum top-up $20; no cards, no identity documents. - Residential: 12 volume tiers from $2.45/GB at 1 GB to $0.95/GB at 10 TB; the tier of a purchase applies to every GB in it; one rate worldwide; traffic never expires. - ISP (static residential): per IP, unlimited traffic, terms of 24 hours ($0.75), 30 days ($1.12), 60 days ($1.06/month) and 90 days ($0.99/month) in the United States; other zones at published multiples; volume discounts of 5 % (10+), 10 % (50+), 20 % (100+) and 25 % (500+). - Datacenter: dedicated IPs with 100 GB of pooled traffic per IP per month; 30 days $0.80, 60 days $0.76/month, 90 days $0.70/month in North America; Europe ×1.15, rest of the world ×1.40; same volume discounts as ISP. - Mobile: rotating 4G/5G pool from $2.62/GB (2 GB) down to $1.58/GB (500 GB); dedicated devices $69/month in the United States and Canada (24-hour test $5.90), Western Europe and Australia ×0.80, Eastern Europe, Türkiye, Brazil, South Africa and Asia ×0.50. - Targeting: country (-cc-), US state (-state-), city (-city-) and ASN (-asn-) as username parameters; sticky sessions with -sid- and -ttl- from 1 minute to 24 hours; rotation on every new connection otherwise. - Gateways: res.proxshift.com and mob.proxshift.com on port 9000 (HTTP/S) and 9001 (SOCKS5); dedicated addresses as ip:8000 (HTTP/S) and ip:8001 (SOCKS5); username-password or IP-whitelist authentication; unlimited concurrent connections. - Sourcing and rules: residential capacity from opt-in, paid pools; acceptable use policy enforced (no attacks, fraud, unauthorized access or anything illegal where the user or the target operate). - Transparency: the documentation is the product contract; every price on the site comes from one public grid; a status page probes every system every five minutes. ## The four networks | Network | What the IP is | Pool size | Best for | Billing | Targeting | From | | --- | --- | --- | --- | --- | --- | --- | | Residential proxies | 70M+ real household IPs, rotating or sticky | 70M+ residential IPs | Scraping, SERP tracking, ad verification | Per GB · traffic never expires | Country, state, city, ASN | $2.45/GB | | ISP proxies | 550K+ static residential IPs on datacenter lines | 550K+ static residential IPs | Accounts, checkout, logins | Per dedicated IP · unlimited traffic | Country, city | $0.99/IP/mo | | Datacenter proxies | 550K+ private IPs built for raw speed | 550K+ datacenter IPs | Bulk, low-sensitivity workloads | Per dedicated IP · 100 GB/mo pooled | Country, state, city | $0.70/IP/mo | | Mobile proxies | 4.9M+ real 4G/5G carrier IPs | 4.9M+ mobile IPs | The most protected targets | Per GB, or a dedicated IP per term | Country, carrier | $2.62/GB | Pool sizes: Residential and mobile figures count distinct IP addresses available over a month, not the number online at one instant; ISP and datacenter figures are the address inventory that orders are drawn from. As of September 2026. ### What the address is | Criterion | Residential | ISP | Datacenter | Mobile | | --- | --- | --- | --- | --- | | Where it comes from | A household device on a consumer ISP, with the owner's consent | A block registered to a consumer ISP, hosted on a wired datacenter uplink | A range announced from a commercial facility | A carrier's 4G/5G network, behind NAT shared by thousands of subscribers | | Pool size | 70M+ addresses in the rotating pool | 550K+ static addresses to order from | 550K+ dedicated addresses to order from | 4.9M+ carrier addresses in the rotating pool | | Who else uses it | A shared pool; you hold one exit only for the length of a session | Nobody. The address is yours for the whole term | Nobody. The address is yours for the whole term | Pool: shared carrier NAT. Dedicated device: yours alone | | How targets score it | Like a home visitor | Like a home visitor, with a datacenter's stability | As hosting: rate-limited or blocked on protected sites | The most tolerated traffic there is; blocking it blocks real customers | ### Behaviour | Criterion | Residential | ISP | Datacenter | Mobile | | --- | --- | --- | --- | --- | | Rotation | New exit on every connection, or held up to 24 hours with a session id | None. The IP is static | None. The IP is static | Pool: per connection or sticky. Device: on demand by link, API or timer | | Targeting | Country, US state, city and ASN from the username | Country and city chosen at the order | Country and city chosen at the order | Country and carrier (ASN) on the pool; fixed on a device | | Speed and latency | A household line; a few hundred milliseconds added | Wired uplink; the fastest residential-grade option | Wired uplink; the fastest of the four | Cellular; fine for pages and apps, not for bulk transfer | | Concurrency | Unlimited | Unlimited | Unlimited | Unlimited | | Delivery | One hostname, parameters in the username | A list of ip:port:user:pass lines | A list of ip:port:user:pass lines | Pool: one hostname. Device: its own ip:port plus a rotation link | ### Money | Criterion | Residential | ISP | Datacenter | Mobile | | --- | --- | --- | --- | --- | | Billing unit | Per GB, tier set by the purchase size, never expires | Per address per term: 24 hours, 30, 60 or 90 days | Per address per term: 30, 60 or 90 days | Pool per GB; device per term from 24 hours to 90 days | | Traffic | Metered, both directions | Unlimited | 100 GB per address each month, pooled across the order | Pool metered; device unlimited | | Location pricing | One rate worldwide | By zone; the United States is the reference | By zone; North America is the reference | Pool: one rate. Devices by zone, cheaper outside North America | | From | $2.45 per GB | $0.99 per address per month | $0.70 per address per month | $2.62 per GB; devices from $31.05 per month | ### Fit | Criterion | Residential | ISP | Datacenter | Mobile | | --- | --- | --- | --- | --- | | Best for | Scraping, SERP, ads, prices, travel, research | Accounts, checkout, anything that must keep one IP | Bulk collection from open sources, monitoring, QA | Social accounts, mobile ads and apps, the hardest targets | | Avoid for | Logins that must never change address | Wide geographic sampling; one address is one place | Targets that fingerprint hosting ranges | Bulk transfer and raw throughput | ## Pricing ### Residential traffic (per GB, worldwide, never expires) | Purchase of at least | Per GB | Total at that size | | --- | --- | --- | | 1 GB | $2.45 | $2.45 | | 2 GB | $2.35 | $4.70 | | 5 GB | $2.10 | $10.50 | | 10 GB | $1.93 | $19.30 | | 25 GB | $1.82 | $45.50 | | 50 GB | $1.75 | $87.50 | | 100 GB | $1.54 | $154 | | 250 GB | $1.40 | $350 | | 500 GB | $1.19 | $595 | | 1 TB | $1.02 | $1,020 | | 5 TB | $0.98 | $4,900 | | 10 TB | $0.95 | $9,500 | ### Mobile traffic, rotating pool (per GB, worldwide, never expires) | Purchase of at least | Per GB | Total at that size | | --- | --- | --- | | 2 GB | $2.62 | $5.24 | | 10 GB | $2.45 | $24.50 | | 50 GB | $2.10 | $105 | | 100 GB | $1.92 | $192 | | 500 GB | $1.58 | $790 | ### ISP proxies (per dedicated IP, unlimited traffic) | Location zone | 24 hours (total per IP) | 30 days (total per IP) | 60 days (total per IP) | 90 days (total per IP) | | --- | --- | --- | --- | --- | | United States (reference) | $0.75 | $1.12 ($1.12/mo) | $2.12 ($1.06/mo) | $2.97 ($0.99/mo) | | Canada & Western Europe (+20 %) | $0.90 | $1.34 ($1.34/mo) | $2.54 ($1.27/mo) | $3.56 ($1.19/mo) | | Rest of Europe (+35 %) | $1.01 | $1.51 ($1.51/mo) | $2.86 ($1.43/mo) | $4.01 ($1.34/mo) | | Asia-Pacific & Brazil (+55 %) | $1.16 | $1.74 ($1.74/mo) | $3.29 ($1.64/mo) | $4.60 ($1.53/mo) | Volume discounts on the whole order: 10 IPs or more take 5 % off, 50 or more 10 %, 100 or more 20 %, 500 or more 25 %. ### Datacenter proxies (per dedicated IP, 100 GB/month pooled) | Location zone | 30 days (total per IP) | 60 days (total per IP) | 90 days (total per IP) | | --- | --- | --- | --- | | United States & Canada (reference) | $0.80 ($0.80/mo) | $1.52 ($0.76/mo) | $2.10 ($0.70/mo) | | Europe (+15 %) | $0.92 ($0.92/mo) | $1.75 ($0.87/mo) | $2.42 ($0.80/mo) | | Asia-Pacific, Middle East, Latin America & Africa (+40 %) | $1.12 ($1.12/mo) | $2.13 ($1.06/mo) | $2.94 ($0.98/mo) | Volume discounts on the whole order: 10 IPs or more take 5 % off, 50 or more 10 %, 100 or more 20 %, 500 or more 25 %. ### Dedicated mobile devices (per device, unlimited traffic) | Location zone | 24 hours (total per IP) | 30 days (total per IP) | 60 days (total per IP) | 90 days (total per IP) | | --- | --- | --- | --- | --- | | United States & Canada (reference) | $5.90 | $69 ($69/mo) | $131.10 ($65.55/mo) | $186.30 ($62.10/mo) | | Western Europe & Australia (−20 %) | $4.72 | $55.20 ($55.20/mo) | $104.88 ($52.44/mo) | $149.04 ($49.68/mo) | | Eastern Europe, Türkiye, Brazil, South Africa & Asia (−50 %) | $2.95 | $34.50 ($34.50/mo) | $65.55 ($32.78/mo) | $93.15 ($31.05/mo) | ### Billing rules **Do prices depend on the country?** Not for traffic: residential and rotating mobile GB cost the same in every country, because the pools are priced on volume alone. Dedicated ISP addresses, datacenter addresses and mobile devices are priced by location zone, since hosting, ISP blocks and carrier plans cost very different amounts from one country to another. The zone tables on this page show every multiple before you order. **Which tier do I get?** The tier of the purchase you make. Buy 100 GB at once and every GB in it costs $1.54; buy 1 GB ten times and each purchase is priced at its own tier. The calculator above shows the exact rate and total for any amount before you commit. **Does traffic expire?** No. Residential and mobile GB stay on your account until you use them. There is no monthly reset, no minimum monthly spend and no plan to keep active. **Is there a subscription?** No. You fund a prepaid wallet and spend it. Dedicated addresses and devices are rented for a term you choose and simply end unless you renew them. If you prefer, switch on automatic renewal per order: off by default, prepaid balance only, and you can turn it off at any time. **What is the smallest amount I can start with?** A top-up of $20. That buys a few GB of residential or mobile traffic, or a single ISP address or mobile device for 24 hours, or a datacenter address for 30 days: enough to run your real workload before scaling. **How do volume discounts work on dedicated addresses?** They apply automatically to the whole order and stack with the term price: 10 IPs or more take 5 % off, 50 or more 10 %, 100 or more 20 %, 500 or more 25 %. Ten addresses on a 90-day term are cheaper per address than one, and a hundred cheaper still. **Are there any fees beyond the prices shown?** None from us: no setup fee, no per-connection or per-thread fee, no overage charge. When a datacenter order uses up its monthly pool of 100 GB per address, speed is reduced until the next cycle or until you add traffic; nothing is billed on top. The only cost outside our control is the network fee of your own crypto transaction when you top up. **Can I get a rate beyond the published ladders?** Yes. Above 10 TB of residential traffic, 500 GB of mobile traffic or 500 dedicated addresses, contact us with your volume and we will quote a rate for it. Everything below those points is priced here, without negotiation. **How do refunds work?** Unused wallet balance can be refunded to the wallet it came from, minus network fees. Traffic already consumed and terms already delivered are not refundable, and a dedicated address that stays unreachable for more than 24 hours is replaced rather than refunded. The refund policy has the details. ## Documentation ### Quickstart (https://proxshift.com/docs/quickstart) Five steps, no SDK to install, any HTTP client. Ten minutes if you already hold some crypto. #### The five steps 1. **Create an account and fund the wallet** Sign up with an email address, then top up from $20 in any listed coin (BTC, ETH, USDT, USDC, LTC, XMR, SOL, TRX, DOGE). The balance is credited when the transaction confirms on its network, usually within minutes, and it never expires. 2. **Copy your gateway credentials** The dashboard shows one username and one password for the shared gateways (residential and mobile). Dedicated ISP, datacenter and mobile-device orders come with their own `ip:port:user:pass` lines instead. 3. **Pick the endpoint for the job** Shared networks are one hostname each; you choose the location from the username, not from the hostname. Dedicated products are their own `ip:port`. Network | Endpoint | HTTP(S) | SOCKS5 | Residential | res.proxshift.com | 9000 | 9001 | Mobile, rotating | mob.proxshift.com | 9000 | 9001 | ISP, datacenter, mobile device | the IP from your list | 8000 | 8001 | 4. **Send the first request** The example asks an IP-echo service what address it sees. `-cc-us` in the username asks for a United States exit; run it twice and you get two different households. cURLPythonNode.jsPHPGocURLCopycurl -x http://USER-cc-us:PASS@res.proxshift.com:9000 https://api.ipify.orgPythonCopyimport requests proxy = "http://USER-cc-us:PASS@res.proxshift.com:9000" r = requests.get("https://api.ipify.org", proxies={"http": proxy, "https": proxy}, timeout=30) print(r.text)Node.jsCopyimport { fetch, ProxyAgent } from "undici"; const dispatcher = new ProxyAgent("http://USER-cc-us:PASS@res.proxshift.com:9000"); const res = await fetch("https://api.ipify.org", { dispatcher }); console.log(await res.text());PHPCopy$ch = curl_init("https://api.ipify.org"); curl_setopt_array($ch, [ CURLOPT_PROXY => "http://res.proxshift.com:9000", CURLOPT_PROXYUSERPWD => "USER-cc-us:PASS", CURLOPT_RETURNTRANSFER => true, ]); echo curl_exec($ch);GoCopyproxyURL, _ := url.Parse("http://USER-cc-us:PASS@res.proxshift.com:9000") client := &http.Client{Transport: &http.Transport{Proxy: http.ProxyURL(proxyURL)}} resp, err := client.Get("https://api.ipify.org") 5. **Target more precisely and hold an IP** Everything is a `-key-value` pair appended to the username: `-city-berlin` inside `-cc-de` for one city, `-sid-a1b2c3` to keep the same IP across requests, `-ttl-30m` to say for how long. The [Targeting & sessions](https://proxshift.com/docs/username-parameters) page lists every parameter. ``` # One Berlin household, held for 30 minutes across requests curl -x http://USER-cc-de-city-berlin-sid-a1b2c3-ttl-30m:PASS@res.proxshift.com:9000 \ https://api.ipify.org ``` > Tip: Verify what you got: paste the IP the echo service returned into any public geolocation database. It should resolve to the country you asked for, on a consumer ISP. #### Where to go next - [Authentication](https://proxshift.com/docs/authentication): Username-password or IP whitelist, and how parameters travel with each. - [Targeting & sessions](https://proxshift.com/docs/username-parameters): Country, state, city, ASN, sticky sessions and their lifetime. - [Code examples](https://proxshift.com/docs/examples): Python, Node.js, PHP, Go, Java, C#, Playwright, Puppeteer, Scrapy and more. - [Errors & troubleshooting](https://proxshift.com/docs/errors): What each status code from the gateway means and what to change. ### Authentication (https://proxshift.com/docs/authentication) Both methods work on every network and on both protocols. Pick per server, mix them freely. #### Choosing a method | | Username and password | IP whitelist | | --- | --- | --- | | Works from | Any IP, including dynamic and cloud ones | The public IPv4 addresses you registered | | Targeting parameters | Appended to the username | Send any username to pass them; the password is ignored | | Credentials in transit | Base64 in the `Proxy-Authorization` header | None | | Best for | Laptops, containers, serverless, browsers | Fixed servers, anti-detect browsers that cannot store a password, Chrome flags | | Rotation | Regenerate the password at any time | Add or remove addresses at any time | #### Username and password Your account has one credential pair for the shared gateways. It is shown in the dashboard under **Credentials** and returned by [`GET /v1/credentials`](https://proxshift.com/docs/api#get-v1-credentials). The username carries the [targeting parameters](https://proxshift.com/docs/username-parameters); the password never changes with them. ```bash # HTTP(S) target through the residential gateway curl -x http://USER-cc-us:PASS@res.proxshift.com:9000 https://api.ipify.org # Same thing over SOCKS5 (socks5h = resolve the hostname at the exit) curl --proxy socks5h://USER-cc-us:PASS@res.proxshift.com:9001 https://api.ipify.org ``` Under the hood an HTTP client sends `Proxy-Authorization: Basic base64(username:password)` on the request or on the `CONNECT`; a SOCKS5 client uses the username/password sub-negotiation (RFC 1929). Every mainstream client does this for you when the credentials are in the proxy URL. > Info: Passwords are generated from letters and digits, so they never need URL-encoding. If you set your own and it contains `@`, `:` or `/`, percent-encode those characters in proxy URLs (`@` becomes `%40`). #### IP whitelist Register the public IPv4 addresses of the machines that will connect, and they can use every endpoint without credentials. Up to 50 addresses per account; changes apply within a minute. 1. Find the address the target will see from your server: `curl https://api.ipify.org` **without** a proxy. 2. Add it under **Settings → Whitelist**, or call [`POST /v1/whitelist`](https://proxshift.com/docs/api#post-v1-whitelist). 3. Connect without a username and password. With no username the exit is chosen worldwide and rotates on every connection. 4. To target, keep sending a username with the parameters you need and any password: a whitelisted address is trusted regardless of the password. ```bash # From a whitelisted server: no credentials at all curl -x http://res.proxshift.com:9000 https://api.ipify.org # Still whitelisted, but with targeting: any password works curl -x http://USER-cc-fr-city-paris:x@res.proxshift.com:9000 https://api.ipify.org ``` > Warn: Whitelisting needs a stable public IP. Machines behind carrier NAT, home connections with dynamic addresses and most serverless platforms should use the password method instead. #### Dedicated ISP, datacenter and mobile devices Each dedicated address comes with its own username and password, printed in your list as `ip:port:user:pass`. The whitelist applies to them too: from a registered server you connect to `ip:8000` with no credentials at all. Parameters are not needed on a dedicated address, since its location is fixed. ```text 203.0.113.42:8000:u7f3a9c:kq2Lm8Pz1r # HTTP(S) 203.0.113.42:8001:u7f3a9c:kq2Lm8Pz1r # SOCKS5, same credentials ``` #### Sub-users A sub-user is an extra credential pair on the shared gateways with its own traffic limit and its own usage line. Create one per client, per project or per teammate so a leaked password only exposes a bounded budget and you can read consumption per line of business. Sub-users are managed in the dashboard and through [`POST /v1/subusers`](https://proxshift.com/docs/api#post-v1-subusers). #### Rotating a password Regenerate from the dashboard or with [`POST /v1/credentials/rotate`](https://proxshift.com/docs/api#post-v1-credentials-rotate). The previous pair keeps working for ten minutes so running jobs can pick up the new one without failing. #### Keeping credentials out of the wrong places - Read them from environment variables or a secret store, never from source control. - Prefer the whitelist on shared or untrusted networks: the hop from you to the gateway is plain HTTP, so a Basic header can be read on the path. - Give each tool a sub-user; revoke the sub-user instead of the account password when a tool is retired. - Strip proxy URLs from logs. Most clients print the full URL, credentials included, on errors. ### Endpoints & ports (https://proxshift.com/docs/endpoints) Location is never in the hostname. Shared gateways read it from the username; dedicated proxies are fixed at the order. #### The table | Network | Endpoint | HTTP(S) | SOCKS5 | Auth | Billing | | --- | --- | --- | --- | --- | --- | | Residential | res.proxshift.com | 9000 | 9001 | user:pass or whitelist | Per GB, never expires | | Mobile, rotating | mob.proxshift.com | 9000 | 9001 | user:pass or whitelist | Per GB, never expires | | ISP | your IP (list) | 8000 | 8001 | user:pass or whitelist | Per IP per term, unlimited traffic | | Datacenter | your IP (list) | 8000 | 8001 | user:pass or whitelist | Per IP per term, 100 GB/IP/mo pooled | | Mobile, dedicated | your device IP | 8000 | 8001 | user:pass or whitelist | Per device per term, unlimited traffic | #### One hostname, every location Connect to `res.proxshift.com` from anywhere and ask for the exit you want in the username: `-cc-jp` for Japan, `-cc-us-state-tx-city-austin` for Austin, `-asn-3320` for Deutsche Telekom customers. There are no per-country hostnames to maintain, so changing market is a string change, not a configuration change. The mobile gateway `mob.proxshift.com` takes the same parameters. #### HTTPS targets For an `https://` URL your client sends `CONNECT host:443` to port 9000 and the gateway opens a tunnel from the chosen exit. TLS runs end to end between your client and the target: the gateway never sees the plaintext, never terminates or re-signs the certificate, and does not alter the SNI. HTTP and HTTPS targets share the same port; there is no separate TLS port for the proxy hop itself. > Warn: The hop from your machine to the gateway is not encrypted. With password authentication the Basic header travels in the clear on that hop; on networks you do not trust, use the [IP whitelist](https://proxshift.com/docs/authentication#ip-whitelist) or connect from a server you control. #### Dedicated addresses An ISP proxy, a datacenter proxy or a mobile device is delivered as an IP address that answers on port 8000 for HTTP(S) and 8001 for SOCKS5. The list in your dashboard, and [`GET /v1/proxies`](https://proxshift.com/docs/api#get-v1-proxies), give one line per address: ```text 203.0.113.42:8000:u7f3a9c:kq2Lm8Pz1r 203.0.113.57:8000:u7f3a9c:kq2Lm8Pz1r 198.51.100.9:8000:d4c1e0:Zt6Hn3Vw9x # a mobile device ``` Username parameters are ignored on dedicated addresses: a dedicated proxy is already one fixed location and one fixed IP. #### IP version and DNS - Exits are IPv4. Targets that only publish an AAAA record are not reachable through the network. - Hostnames are resolved on the exit side, so the target sees a DNS lookup from the same country as the request. With SOCKS5 use the `socks5h://` scheme so your client hands the hostname to the proxy instead of resolving it locally. - `res.proxshift.com` and `mob.proxshift.com` resolve to the gateway cluster; do not pin their addresses in configuration, they change as capacity is added. #### Ports on the target Any TCP port on the destination is allowed, with one exception: outbound port 25 (SMTP) is blocked on every network. UDP is not carried; see [Protocols](https://proxshift.com/docs/protocols). #### Timeouts and keep-alive - A connection to the gateway with no traffic for 60 seconds is closed. Reopen it; the next connection picks a fresh exit unless you hold one with `-sid-`. - Transfers have no duration limit as long as data flows, so large downloads and long-polling work. - Keep-alive is honoured. Requests reusing one connection share one exit for the life of that connection; see [rotation](https://proxshift.com/docs/username-parameters#rotation-and-sessions). ### Targeting & sessions (https://proxshift.com/docs/username-parameters) Country, US state, city, provider, session identity and lifetime. Six parameters, in any order, on both shared gateways. #### Syntax Start with your username, then append `-key-value` pairs. Keys and values are lowercase; order does not matter; the password is unchanged. With no parameter at all the exit is chosen from any country and changes on every connection. ```text USER-cc-us-state-tx-city-austin-sid-a1b2c3-ttl-30m:PASS │ │ │ │ │ │ │ │ │ │ │ └─ hold it for 30 minutes │ │ │ │ └─ session id: same id, same IP │ │ │ └─ city (letters and digits only) │ │ └─ US state (United States only) │ └─ country, ISO 3166-1 alpha-2 └─ your username ``` #### Parameters | Parameter | Values | Meaning | | --- | --- | --- | | -cc- | Two-letter country code: `us`, `de`, `br`, `jp` | Exit from that country. 199 countries on residential; the mobile pool covers the countries listed at checkout. | | -state- | US state code: `tx`, `ca`, `ny` | Exit from that state. Requires `-cc-us`; not available for other countries. | | -city- | City name, lowercase, letters and digits only: `newyork`, `berlin`, `saopaulo` | Exit from that city. Requires `-cc-`. Each [country page](https://proxshift.com/locations) lists its available cities with the exact value. | | -asn- | Autonomous system number without the `AS` prefix: `7922`, `3320` | Exit announced by that provider. Combine with `-cc-`. On the mobile pool this is how you pick a carrier. | | -sid- | Letters and digits, up to 32 characters: `a1b2c3`, `job42` | Sticky session. Requests carrying the same id share one exit until the lifetime ends or the device goes offline. A new id means a new IP. | | -ttl- | Minutes or hours, from `1m` to `24h`: `10m`, `2h` | Lifetime of a sticky session, counted from its first request. Default `10m` when `-sid-` is present without `-ttl-`. | #### Rotation and sessions Without `-sid-` the gateway picks a new exit for **every new connection** it receives. Clients that keep a connection alive, or that send many requests through one `CONNECT` tunnel, keep the same exit for as long as that connection lives. To rotate on every request, disable keep-alive or close the connection after each call; to keep one IP across connections, use a session id. - Same `-sid-` value, same IP, on any number of parallel connections. Run as many sessions at once as you need; there is no cap. - When the lifetime expires or the household disconnects, the next request with that id gets a **new** IP that still matches the other parameters. Design for this: an IP change mid-flow is possible on any residential network. - To force a change immediately, change the id. Ids are scoped to your account and cost nothing. - Sticky sessions exist on the residential and mobile pools. Dedicated ISP, datacenter and mobile-device proxies are one fixed IP and ignore `-sid-` and `-ttl-`. #### Examples | You want | Username | | --- | --- | | A new IP in any country on every connection | USER | | A new United States IP on every connection | USER-cc-us | | A Texas household | USER-cc-us-state-tx | | Any IP in Berlin | USER-cc-de-city-berlin | | One Berlin IP held for ten minutes | USER-cc-de-city-berlin-sid-7f3a9 | | One Japanese IP held for two hours | USER-cc-jp-sid-tokyo1-ttl-2h | | A Comcast subscriber (AS7922) | USER-cc-us-asn-7922 | | Deutsche Telekom mobile customers, held 15 minutes | USER-cc-de-asn-3320-sid-m1-ttl-15m | | Twenty parallel Brazilian sessions | USER-cc-br-sid-w01 … USER-cc-br-sid-w20 | #### City names A city value is the city name in lowercase ASCII with spaces, hyphens, apostrophes and accents removed: `New York` becomes `newyork`, `São Paulo` becomes `saopaulo`, `Düsseldorf` becomes `dusseldorf`, `Frankfurt am Main` is listed as `frankfurt`. Use the value printed on the country page rather than guessing; that is the exact string the gateway matches. #### What happens when a parameter cannot be honoured | Case | Response | What to do | | --- | --- | --- | | Unknown key or malformed value (`-country-us`, `-ttl-90x`) | `400 Bad Request` | Fix the string; the response body names the parameter. | | `-city-` or `-state-` without `-cc-`, or `-state-` outside the US | `400 Bad Request` | Add `-cc-us` or drop the parameter. | | No exit currently online for the combination (a small city plus one ASN, for instance) | `502 Bad Gateway` | Retry, then broaden: drop `-asn-`, then `-city-`. | | Parameters sent to a dedicated address | Ignored | Nothing; the IP is fixed. | > Tip: Start broad and narrow down. Country-level targeting has the deepest pools and the highest success rates; add city and ASN only when the job needs them, and keep sticky lifetimes as short as the flow allows. ### Residential (https://proxshift.com/docs/residential) Household IPs from consumer ISPs in 199 countries, rotating or sticky, billed per GB from $2.45 with no expiry. #### At a glance - **Endpoint**: `res.proxshift.com` on 9000 (HTTP/HTTPS) and 9001 (SOCKS5) - **Exits**: Real devices on consumer connections, with the owner's consent, in 199 countries - **Rotation**: A new exit on every new connection, or one exit held with `-sid-` for up to 24 hours - **Targeting**: Country everywhere, US state, city where listed, ASN - **Billing**: Per GB at the tier of the purchase, from $2.45 to $0.95; traffic never expires - **Concurrency**: Unlimited connections and sessions #### How the pool works Each request enters the gateway, which selects a device matching your parameters and relays the connection through it. The target sees the device's address, its ISP and its city. Devices join and leave the pool as their owners connect and disconnect, which is why a sticky session can end before its lifetime and why very narrow targeting sometimes finds nobody online. #### Rotation and sticky sessions The default is rotation: every new connection to the gateway gets a different exit. Add `-sid-` to hold one exit and `-ttl-` to say for how long (default 10 minutes, maximum 24 hours). Multi-step flows such as search then paginate, or login then act, belong on a sticky session; independent fetches belong on rotation. Details and examples on [Targeting & sessions](https://proxshift.com/docs/username-parameters). #### Targeting levels | Level | Parameter | Coverage | Typical use | | --- | --- | --- | --- | | Country | -cc- | 199 countries | Localized content, geo-blocks, per-market pricing | | State | -state- | United States only | State-specific pricing, compliance and ads | | City | -city- | Where the country page lists cities | Local SERPs, store availability, delivery rules | | Provider | -asn- | Any AS with devices online | Reproducing a given ISP's audience, provider-level tests | #### What you pay for Metered traffic is every byte that crosses the gateway in both directions: request and response, headers and TLS records included. Connections that fail before reaching the target are not billed. The rate is set by the size of the purchase: 100 GB bought at once cost $1.54 per GB, and that rate applies to the whole purchase. Traffic stays on the account until used; there is no monthly reset. The full ladder is on [Wallet & billing](https://proxshift.com/docs/billing#residential-and-mobile-traffic). #### Performance expectations - Throughput is that of a household line: fine for pages, APIs and media, below a wired datacenter link for bulk transfer. Give clients a connect timeout of at least 10 seconds and a read timeout of 30. - Latency includes the hop to the device. Expect a few hundred milliseconds more than a direct request, more for distant countries. - A small share of connections fail because a device went offline mid-request. Retry once on a connection error or a `502`; with rotation the retry already uses a different exit. #### Best practices - Match the exit to the market: scrape the German store from `-cc-de`, not from a nearby country. - Keep sticky sessions as short as the flow needs. Long lifetimes lower success rates because devices come and go. - Pace per domain. There is no cap on your side, and a polite request rate keeps the pool clean for everyone, including your next job. - Block images, fonts and trackers in headless browsers; HTML is a small fraction of a page and you pay per GB. - Use the [country pages](https://proxshift.com/locations) to check the cities and providers available before you narrow a job. #### Related - [Targeting & sessions](https://proxshift.com/docs/username-parameters): Every parameter, with examples and error cases. - [Wallet & billing](https://proxshift.com/docs/billing): The per-GB ladder and how purchases reach a tier. - [Residential proxies](https://proxshift.com/residential-proxies): Prices, coverage and the full product page. ### ISP (https://proxshift.com/docs/isp) IPs registered to consumer ISPs and hosted on wired uplinks, yours alone for the term, unlimited traffic, in 33 countries. #### At a glance - **Endpoint**: One `ip:port` per proxy: 8000 for HTTP(S), 8001 for SOCKS5 - **Exits**: Addresses registered to consumer ISPs, hosted in datacenters, 33 countries - **Rotation**: None. The IP is fixed for the whole term - **Billing**: Per IP per term (24 hours, 30, 60 or 90 days), from $0.99 per IP per month in the United States on 90 days; other regions by zone - **Traffic**: Unlimited, unmetered - **Concurrency**: Unlimited connections per IP #### Ordering Choose a country, a quantity and a term. Prices depend on the location zone; the United States is the reference and other zones are published multiples of it. Volume discounts apply to the whole order automatically: 10 IPs or more take 5 % off, 50 or more 10 %, 100 or more 20 %, 500 or more 25 %. The 24-hour term exists to test a location before committing. #### Your list Addresses are provisioned within minutes and appear in the dashboard and in [`GET /v1/proxies`](https://proxshift.com/docs/api#get-v1-proxies) as `ip:port:user:pass` lines and as JSON. Every line is an independent proxy; there is no gateway in front of it, so latency is that of the datacenter hosting the address. ```bash # With the credentials from the list curl -x http://u7f3a9c:kq2Lm8Pz1r@203.0.113.42:8000 https://api.ipify.org # From a whitelisted server curl -x http://203.0.113.42:8000 https://api.ipify.org ``` #### Authentication Each address has its own username and password, and the account [whitelist](https://proxshift.com/docs/authentication#ip-whitelist) applies to all of them. Username parameters are ignored: the location is the address itself. #### Traffic and concurrency Nothing is metered on an ISP proxy. Stream, download, keep long-lived sessions open and run as many parallel connections as the target tolerates; the per-IP price is the whole bill. #### Renewal, expiry and replacement - Renew before the end of the term, from the dashboard or with [`POST /v1/orders/{id}/renew`](https://proxshift.com/docs/api#post-v1-orders-id-renew), to keep the same addresses. An expired order releases its IPs and they cannot be recovered. - If an address stays unreachable for more than 24 hours it is replaced for the remainder of the term at no charge. A replacement is a different IP; sessions bound to the old one must be moved. - Blocks by a specific target are not a fault of the address and are not grounds for replacement. Test with the 24-hour term first when a target is known to be strict. #### Running accounts on a static IP - One account, one IP, one browser profile. Shared exits link accounts together. - Keep the account in the country where it was created and use an IP from that country. - Warm up: new accounts on new IPs should behave slowly for days. Automation at full speed on day one is the signature platforms look for. - Renew early. An account that suddenly appears from a new address is treated as a new device. #### Related - [ISP proxies](https://proxshift.com/isp-proxies): Prices by zone, terms and the 33 countries. - [Social media management](https://proxshift.com/use-cases/social-media-management): The use case that most often calls for ISP addresses. - [Authentication](https://proxshift.com/docs/authentication): Whitelist a server so it needs no password. ### Datacenter (https://proxshift.com/docs/datacenter) The fastest network we sell. Fixed addresses on wired uplinks in 37 countries, with 100 GB per IP each month pooled across the order. #### At a glance - **Endpoint**: One `ip:port` per proxy: 8000 for HTTP(S), 8001 for SOCKS5 - **Exits**: Addresses in carrier-grade facilities, 60+ cities in 37 countries - **Rotation**: None. Fixed addresses for the term - **Billing**: Per IP per term (30, 60 or 90 days), from $0.70 per IP per month in North America on 90 days; other regions by zone - **Traffic**: 100 GB per IP each month, pooled across all IPs of the order - **Concurrency**: Unlimited connections per IP #### Ordering Pick locations (country, and city where offered), a quantity and a term. One order can mix cities. North America is the reference zone; Europe and the rest of the world follow at published multiples. Volume discounts apply automatically to the whole order: 10 IPs or more take 5 % off, 50 or more 10 %, 100 or more 20 %, 500 or more 25 %. #### The traffic pool Every IP in an order contributes 100 GB to that order's monthly pool, and any IP of the order can draw from it. Ten IPs share 1000 GB regardless of which one does the work. The cycle starts on the order date and resets every month; unused pool does not carry over. Usage is visible per order in the dashboard and in [`GET /v1/usage`](https://proxshift.com/docs/api#get-v1-usage). | Situation | Behaviour | | --- | --- | | Pool below the limit | Full speed on every IP | | Pool exhausted | Speed is reduced until the next cycle; nothing is blocked and no request fails because of the pool | | You need more this month | Add traffic to the order or add IPs (each brings 100 GB) from the dashboard or the API | #### Your list and authentication Same delivery as ISP proxies: `ip:port:user:pass` lines and JSON in the dashboard and in [`GET /v1/proxies`](https://proxshift.com/docs/api#get-v1-proxies), one username and password per address, whitelist supported. Parameters in the username are ignored. #### Performance Wired uplinks in facilities on major internet exchanges: the lowest and most predictable latency of the four networks, and the right choice for bulk collection, monitoring and APIs that do not fingerprint hosting ranges. Targets that score visitors often flag datacenter ranges; for those use [residential](https://proxshift.com/docs/residential) or [mobile](https://proxshift.com/docs/mobile). #### Renewal and replacement Renew before the end of the term to keep the same addresses. An address unreachable for more than 24 hours is replaced for the remainder of the term. Blocks by a target are not a fault of the address. #### Related - [Datacenter proxies](https://proxshift.com/datacenter-proxies): Prices by zone, the pool policy and the 37 countries. - [Web scraping](https://proxshift.com/use-cases/web-scraping): When datacenter is enough and when it is not. - [Wallet & billing](https://proxshift.com/docs/billing): How terms, renewals and pools are charged. ### Mobile (https://proxshift.com/docs/mobile) Real 4G/5G devices on real carriers. Rotate through the pool from $2.62 per GB, or rent a modem and decide yourself when its IP changes. #### Two modes | | Rotating pool | Dedicated device | | --- | --- | --- | | Endpoint | `mob.proxshift.com`, 9000 / 9001 | The device's own `ip:8000` / `ip:8001` | | IP behaviour | New carrier IP per connection, or sticky with `-sid-` | One IP, yours alone, changed when you say so | | Targeting | `-cc-`, carrier with `-asn-`, `-sid-`, `-ttl-` | Fixed at the order: country and carrier | | Billing | Per GB, from $2.62, same rate in every country, never expires | Per device per term (24 hours, 30, 60, 90 days), by country; unlimited traffic | | Best for | Collection at scale from mobile-first targets | Accounts and flows that must keep one phone-like footprint | #### The rotating pool Everything on [Targeting & sessions](https://proxshift.com/docs/username-parameters) applies to `mob.proxshift.com`. Pick the country with `-cc-`; pick a carrier with `-asn-` and its AS number, listed on each [country page](https://proxshift.com/locations); hold an IP with `-sid-`. Carrier addresses are shared by thousands of subscribers behind NAT, which is exactly why targets tolerate them. ```bash # Any US carrier, new IP per connection curl -x http://USER-cc-us:PASS@mob.proxshift.com:9000 https://api.ipify.org # Deutsche Telekom (AS3320), held for 15 minutes curl -x http://USER-cc-de-asn-3320-sid-m1-ttl-15m:PASS@mob.proxshift.com:9000 https://api.ipify.org ``` #### Dedicated devices A dedicated device is a physical modem with an unlimited carrier plan, hosted in the country you chose. It is delivered like any dedicated proxy, as `ip:8000` and `ip:8001` with its own credentials, and it serves you alone for the term. Traffic is unmetered. Prices depend on the country because plans, hardware and hosting do; the United States and Canada are the reference. #### Rotating the IP of a device You control when a device takes a new address from its carrier. Three ways, all returning the new IP: | Method | How | Use it for | | --- | --- | --- | | Rotation link | A signed URL shown in the dashboard; a simple `GET`, no token needed | Anti-detect browsers, schedulers and tools that can only call a URL | | API call | [`POST /v1/devices/{id}/rotate`](https://proxshift.com/docs/api#post-v1-devices-id-rotate) with your Bearer token | Your own code, before a new session starts | | Timer | `rotate_every_minutes` on the device, set in the dashboard or with [`PATCH /v1/devices/{id}`](https://proxshift.com/docs/api#patch-v1-devices-id) | Hands-off jobs that want a fresh IP every N minutes | ```bash # On demand, from your code curl -X POST https://api.proxshift.com/v1/devices/dev_8k2m/rotate \ -H "Authorization: Bearer TOKEN" # Read the current IP curl https://api.proxshift.com/v1/devices/dev_8k2m -H "Authorization: Bearer TOKEN" ``` - A rotation takes a few seconds. Connections in flight through the device are dropped; open new ones once the call returns. - The new address comes from the same carrier and country. Carriers recycle addresses, so a rotation can occasionally return an IP the device held before. - Rotations are unlimited and free. Rotate when the platform would expect a change (a new session, a new day), not on every request. #### Best practices for accounts - One account per device, in the account's home country and on a carrier its audience actually uses. - Keep the browser profile and the device together; moving an account between devices or countries is what triggers verification. - Rotate deliberately: a new IP per session looks like a phone; a new IP per action does not. - For scheduled posting on many accounts, the pool with short sticky sessions is often enough; reserve devices for the accounts that matter most. #### Related - [Mobile proxies](https://proxshift.com/mobile-proxies): Both price ladders and the countries with devices. - [API reference](https://proxshift.com/docs/api#devices): Devices, rotation and usage endpoints. - [Social media management](https://proxshift.com/use-cases/social-media-management): A full recipe for accounts on mobile and ISP IPs. ### Protocols (https://proxshift.com/docs/protocols) Standard protocols, no custom client. This page is the precise behaviour for people who need to know what happens on the wire. #### Cheat sheet | Target | Proxy URL in your client | Port | | --- | --- | --- | | `http://` and `https://` URLs | http://USER:PASS@res.proxshift.com:9000 | 9000 | | Anything over TCP, hostname resolved at the exit | socks5h://USER:PASS@res.proxshift.com:9001 | 9001 | | Same, hostname resolved by your machine | socks5://USER:PASS@res.proxshift.com:9001 | 9001 | | Dedicated address, HTTP(S) | http://USER:PASS@203.0.113.42:8000 | 8000 | | Dedicated address, SOCKS5 | socks5h://USER:PASS@203.0.113.42:8001 | 8001 | #### HTTP For a plain `http://` target your client sends the request with an absolute URI and a `Proxy-Authorization` header to port 9000. The gateway strips that header, relays the request through the exit and streams the response back. HTTP/1.1 with keep-alive is supported; a kept-alive connection keeps its exit (see [rotation](https://proxshift.com/docs/username-parameters#rotation-and-sessions)). #### HTTPS For an `https://` target the client sends `CONNECT host:443` and the gateway opens a raw tunnel from the exit. The TLS handshake happens between your client and the target through that tunnel: the gateway never decrypts, inspects or re-signs anything, and the certificate you verify is the target's own. HTTP/2 and HTTP/3-over-TCP fallbacks negotiated inside the tunnel work as they would directly. #### SOCKS5 - RFC 1928 with username/password authentication (RFC 1929) or no authentication from a whitelisted address. - `CONNECT` to any TCP port except 25. `BIND` and `UDP ASSOCIATE` are not supported: no UDP, no inbound connections. - Send the hostname (address type 0x03) so the exit resolves it: that is what `socks5h://` means in curl, Python and Node. If your client resolves locally and sends an IP, the request still works but the DNS lookup happened on your side. - Choose SOCKS5 for non-HTTP TCP protocols and for clients that only speak SOCKS; for web traffic the HTTP port is equivalent. #### Headers The gateway removes `Proxy-Authorization` and `Proxy-Connection` and adds nothing: no `Via`, no `X-Forwarded-For`, no `X-Real-IP`. What the target receives is your request as the exit device would send it, which is the point of the network. Set `User-Agent`, `Accept-Language` and the rest to match the exit's country yourself. #### Not supported - UDP in any form (QUIC falls back to TCP in every browser when a proxy is configured). - IPv6 targets: exits are IPv4. - TLS to the proxy port itself (`https://` as the **proxy** scheme). The hop to the gateway is plain; see [Endpoints](https://proxshift.com/docs/endpoints#https-targets). - FTP, SMTP on port 25, and protocols that require the proxy to open a connection back to you. ### Code examples (https://proxshift.com/docs/examples) Every snippet fetches `https://api.ipify.org` through a United States residential exit and prints the IP. Swap the username parameters and the target, nothing else changes. #### Command line **cURL** ```curl # HTTP(S) proxy curl -x http://USER-cc-us:PASS@res.proxshift.com:9000 https://api.ipify.org # SOCKS5 with remote DNS curl --proxy socks5h://USER-cc-us:PASS@res.proxshift.com:9001 https://api.ipify.org # Sticky session for 30 minutes, verbose to see the CONNECT curl -v -x http://USER-cc-us-sid-a1b2c3-ttl-30m:PASS@res.proxshift.com:9000 https://api.ipify.org ``` **wget** ```wget https_proxy=http://USER-cc-us:PASS@res.proxshift.com:9000 \ http_proxy=http://USER-cc-us:PASS@res.proxshift.com:9000 \ wget -qO- https://api.ipify.org ``` **Environment variables** ```env # Most CLI tools and many libraries honour these export HTTP_PROXY=http://USER-cc-us:PASS@res.proxshift.com:9000 export HTTPS_PROXY=http://USER-cc-us:PASS@res.proxshift.com:9000 export NO_PROXY=localhost,127.0.0.1 curl https://api.ipify.org ``` #### Python **requests** ```requests import requests proxy = "http://USER-cc-us:PASS@res.proxshift.com:9000" session = requests.Session() session.proxies = {"http": proxy, "https": proxy} r = session.get("https://api.ipify.org", timeout=30) print(r.text) # Sticky: build the username per session id def proxy_for(sid: str, cc: str = "us", ttl: str = "10m") -> str: return f"http://USER-cc-{cc}-sid-{sid}-ttl-{ttl}:PASS@res.proxshift.com:9000" ``` **httpx** ```httpx import httpx proxy = "http://USER-cc-us:PASS@res.proxshift.com:9000" with httpx.Client(proxy=proxy, timeout=30) as client: print(client.get("https://api.ipify.org").text) # async # async with httpx.AsyncClient(proxy=proxy) as client: ... ``` **aiohttp** ```aiohttp import asyncio import aiohttp async def main(): auth = aiohttp.BasicAuth("USER-cc-us", "PASS") async with aiohttp.ClientSession() as session: async with session.get("https://api.ipify.org", proxy="http://res.proxshift.com:9000", proxy_auth=auth, timeout=30) as r: print(await r.text()) asyncio.run(main()) ``` **Scrapy** ```scrapy import scrapy class IpSpider(scrapy.Spider): name = "ip" def start_requests(self): # HttpProxyMiddleware (enabled by default) reads credentials from the URL yield scrapy.Request( "https://api.ipify.org", meta={"proxy": "http://USER-cc-us:PASS@res.proxshift.com:9000"}, ) def parse(self, response): yield {"ip": response.text} ``` #### Node.js **undici / fetch** ```undici import { fetch, ProxyAgent } from "undici"; const dispatcher = new ProxyAgent("http://USER-cc-us:PASS@res.proxshift.com:9000"); const res = await fetch("https://api.ipify.org", { dispatcher }); console.log(await res.text()); ``` **axios** ```axios import axios from "axios"; import { HttpsProxyAgent } from "https-proxy-agent"; const agent = new HttpsProxyAgent("http://USER-cc-us:PASS@res.proxshift.com:9000"); const { data } = await axios.get("https://api.ipify.org", { httpsAgent: agent, proxy: false, // let the agent handle it }); console.log(data); ``` **Playwright** ```playwright import { chromium } from "playwright"; const browser = await chromium.launch({ proxy: { server: "http://res.proxshift.com:9000", username: "USER-cc-us-sid-a1b2c3-ttl-30m", password: "PASS", }, }); const page = await browser.newPage(); await page.goto("https://api.ipify.org"); console.log(await page.textContent("body")); await browser.close(); ``` **Puppeteer** ```puppeteer import puppeteer from "puppeteer"; const browser = await puppeteer.launch({ args: ["--proxy-server=res.proxshift.com:9000"], }); const page = await browser.newPage(); await page.authenticate({ username: "USER-cc-us-sid-a1b2c3", password: "PASS" }); await page.goto("https://api.ipify.org"); console.log(await page.evaluate(() => document.body.innerText)); await browser.close(); ``` #### PHP **cURL** ```curl $ch = curl_init("https://api.ipify.org"); curl_setopt_array($ch, [ CURLOPT_PROXY => "http://res.proxshift.com:9000", CURLOPT_PROXYUSERPWD => "USER-cc-us:PASS", CURLOPT_RETURNTRANSFER => true, CURLOPT_TIMEOUT => 30, ]); echo curl_exec($ch); ``` **Guzzle** ```guzzle $client = new \GuzzleHttp\Client(); $response = $client->get('https://api.ipify.org', [ 'proxy' => 'http://USER-cc-us:PASS@res.proxshift.com:9000', 'timeout' => 30, ]); echo $response->getBody(); ``` #### Go, Java and C# **Go** ```go package main import ( "fmt" "io" "net/http" "net/url" ) func main() { proxyURL, _ := url.Parse("http://USER-cc-us:PASS@res.proxshift.com:9000") client := &http.Client{Transport: &http.Transport{Proxy: http.ProxyURL(proxyURL)}} resp, err := client.Get("https://api.ipify.org") if err != nil { panic(err) } defer resp.Body.Close() body, _ := io.ReadAll(resp.Body) fmt.Println(string(body)) } ``` **Java (OkHttp)** ```java import okhttp3.*; import java.net.InetSocketAddress; import java.net.Proxy; Proxy proxy = new Proxy(Proxy.Type.HTTP, new InetSocketAddress("res.proxshift.com", 9000)); OkHttpClient client = new OkHttpClient.Builder() .proxy(proxy) .proxyAuthenticator((route, response) -> response.request().newBuilder() .header("Proxy-Authorization", Credentials.basic("USER-cc-us", "PASS")) .build()) .build(); try (Response res = client.newCall(new Request.Builder().url("https://api.ipify.org").build()).execute()) { System.out.println(res.body().string()); } // java.net.http.HttpClient: Basic auth on CONNECT is disabled by default since Java 8u111. // Start the JVM with -Djdk.http.auth.tunneling.disabledSchemes= to enable it. ``` **C#** ```csharp using System.Net; var handler = new HttpClientHandler { Proxy = new WebProxy("http://res.proxshift.com:9000") { Credentials = new NetworkCredential("USER-cc-us", "PASS") }, UseProxy = true, }; using var http = new HttpClient(handler); Console.WriteLine(await http.GetStringAsync("https://api.ipify.org")); ``` #### Browsers and anti-detect tools - Chrome's `--proxy-server` flag takes no credentials. Use Playwright or Puppeteer (they answer the auth challenge for you), or [whitelist](https://proxshift.com/docs/authentication#ip-whitelist) the machine and use the flag alone. - Selenium has no built-in proxy authentication either; the whitelist is the reliable route. - Anti-detect browsers (Multilogin, GoLogin, AdsPower, Dolphin and the like) accept a `host:port:user:pass` line per profile. Paste the dedicated address line, or the gateway with a unique `-sid-` per profile. - Firefox and Chrome ask for the proxy password once per session when configured manually; automation should not rely on that prompt. > Tip: Whatever the client, test with `https://api.ipify.org` first and compare against a direct request. If both print the same IP the proxy is not being used: check environment variables, `NO_PROXY` and whether the library expects `proxy` or `proxies`. ### Errors & troubleshooting (https://proxshift.com/docs/errors) Gateway errors come with a short reason in the body. Target errors pass through untouched. Telling the two apart is most of troubleshooting. #### Responses from the gateway | Status | Reason in the body | Cause | Fix | | --- | --- | --- | --- | | 407 Proxy Authentication Required | invalid_credentials | Wrong username or password, or the connecting IP is not whitelisted and no credentials were sent | Copy the pair from the dashboard again; check the whitelist against `curl https://api.ipify.org` run without a proxy | | 400 Bad Request | invalid_parameter: … | A username parameter is unknown or malformed, or the combination is invalid (`-state-` outside the US, `-city-` without `-cc-`) | Fix the string named in the body; see [Targeting & sessions](https://proxshift.com/docs/username-parameters) | | 402 Payment Required | insufficient_balance | No traffic left on the pool network you are using, or the sub-user reached its limit | Buy traffic or raise the sub-user limit; check [`GET /v1/balance`](https://proxshift.com/docs/api#get-v1-balance) | | 403 Forbidden | blocked_destination | The destination or port is not allowed (port 25, or a target on our deny list), or the account is suspended | Read the reason; contact us if you believe a destination is wrongly listed | | 502 Bad Gateway | no_exit_available / exit_failed | No device online for the parameters, or the chosen device dropped mid-request | Retry once (rotation already picks another exit); broaden the targeting if it repeats | | 504 Gateway Timeout | target_timeout | The target did not answer through the exit within the time limit | Retry with a new IP; raise your client timeout if the target is slow by nature | > Info: The gateway never answers `429`. There is no rate limit on your side; a `429` always comes from the target and means you should pace requests to that domain or spread them over more sessions. #### Gateway error or target error? A gateway error arrives before any byte from the target: on an HTTPS request it is the response to the `CONNECT`, which most clients surface as a connection or proxy error rather than an HTTP response. A target error arrives inside the tunnel with the target's own headers and body. `curl -v` shows the difference immediately: look at which response follows `CONNECT`. #### Diagnostic checklist 1. Run the simplest request: `curl -x http://USER:PASS@res.proxshift.com:9000 https://api.ipify.org` with no parameters. If it works, the problem is in a parameter or in your client. 2. Check the proxy scheme: the proxy URL starts with `http://` (or `socks5h://` on 9001), never `https://`, even for HTTPS targets. 3. Add parameters back one at a time. `400` names the bad one; `502` on a narrow combination means nobody is online there right now. 4. Whitelist users: compare the address in **Settings → Whitelist** with the output of `curl https://api.ipify.org` **without** proxy, run on the same machine. Cloud instances often egress through a NAT gateway with a different address. 5. Check the balance of the network you are actually using: residential and mobile traffic are separate balances. 6. Look for environment variables (`HTTP_PROXY`, `HTTPS_PROXY`, `ALL_PROXY`, `NO_PROXY`) that override what you pass in code. 7. If the TLS certificate fails to verify, something between you and the gateway intercepts TLS (corporate proxy, antivirus). The gateway never touches certificates. #### Symptoms and their usual cause | You see | Usually means | Do this | | --- | --- | --- | | `curl: (56) Received HTTP code 407 from proxy after CONNECT` | Credentials rejected | Re-copy them; percent-encode special characters if you set your own password | | The same IP on every request | Your client reuses one keep-alive connection, or you left a `-sid-` in the username | Close connections between requests or drop the session id | | A different IP on every request although `-sid-` is set | The lifetime is shorter than the gap between requests, or the id changes per request (a random value in a template) | Fix the id, raise `-ttl-` | | `Connection reset by peer` mid-download | The household went offline | Retry; with rotation it already uses another exit; on a sticky session the next request gets a new IP | | Works in curl, fails in the browser | The browser has no proxy password or the flag ignores credentials | Use Playwright or Puppeteer authentication, or the [whitelist](https://proxshift.com/docs/authentication#ip-whitelist) | | Target answers 403 or a CAPTCHA | The target scores the visit, not the proxy | Move to residential or mobile, add a sticky session for multi-step flows, match headers to the exit country, pace per domain | | Everything is slow | Distant exit or a household on a weak line | Choose the country closest to the target, keep sessions short so the next one lands on a better line, or use datacenter or ISP for raw speed | | `SSL certificate problem` | TLS interception on your side | Remove the interception or trust its root; the gateway is not involved | #### Still stuck Send us the exact request (credentials removed), the timestamp in UTC, the status and body you received and the exit IP if the request went through. The [contact page](https://proxshift.com/contact) explains how to reach the team; account holders open a ticket from the dashboard. ### Wallet & billing (https://proxshift.com/docs/billing) Top up from $20, buy traffic or rent addresses from the balance. Nothing expires, nothing renews without you. #### Funding the wallet 1. Choose a coin: BTC, ETH, USDT, USDC, LTC, XMR, SOL, TRX, DOGE. The dashboard shows an address and the exact amount for the top-up you entered. 2. Send exactly that amount. Under-payments are credited at the value received; over-payments are credited in full. 3. The balance is credited in USD when the transaction reaches the confirmation depth of its network, usually within minutes. Every top-up is listed with its transaction hash. - **Minimum top-up**: $20 - **Top-up bonus**: +10% from $100, +25% from $250, +40% from $500, +50% from $1,000. Credited with the top-up on its own ledger line; spent like balance, never paid out. - **Currency of the balance**: USD; conversion at the exchange rate when the transaction is detected - **Expiry**: None, on the balance and on the traffic bought with it - **Refunds**: See the [refund policy](https://proxshift.com/legal/refunds) #### Residential and mobile traffic Traffic is bought in GB from the wallet. The price per GB is set by the size of the purchase and applies to every GB in it, so buying a month of traffic at once is cheaper than the same volume in small top-ups. Residential and mobile are separate balances with separate ladders. Both never expire. | Purchase of at least | Residential, per GB | Total for the tier size | | --- | --- | --- | | 1 GB | $2.45 | $2.45 | | 2 GB | $2.35 | $4.70 | | 5 GB | $2.10 | $10.50 | | 10 GB | $1.93 | $19.30 | | 25 GB | $1.82 | $45.50 | | 50 GB | $1.75 | $87.50 | | 100 GB | $1.54 | $154 | | 250 GB | $1.40 | $350 | | 500 GB | $1.19 | $595 | | 1,000 GB | $1.02 | $1,020 | | 5,000 GB | $0.98 | $4,900 | | 10,000 GB | $0.95 | $9,500 | The mobile ladder and the current figures for every network are on the [pricing page](https://proxshift.com/pricing); each product page shows its own ladder and quote tool. #### Dedicated products - ISP proxies, datacenter proxies and mobile devices are paid per address for a term, taken from the wallet at the order. Terms are 24 hours (ISP and mobile devices), 30, 60 and 90 days; longer terms cost less per month. - Prices depend on the location zone of each address; the quote tools and the order form show the exact total before you confirm. - Volume discounts apply automatically to the whole order (ISP: 10 IPs or more take 5 % off, 50 or more 10 %, 100 or more 20 %, 500 or more 25 %). - Renew before the end of the term to keep the same addresses, or switch on automatic renewal for that order: it is off by default, only ever uses your wallet balance, emails you each time and can be turned off at any moment. An order that is not renewed simply ends and releases its IPs. - Datacenter orders carry a traffic pool of 100 GB per IP per month, reset on the order date each month. Traffic can be added to an order at any time; see [Datacenter](https://proxshift.com/docs/datacenter#the-traffic-pool). #### Sub-user limits A [sub-user](https://proxshift.com/docs/authentication#sub-users) draws from the account's traffic balance up to its own limit. Limits are a ceiling, not a purchase: they let you cap a client or a project without moving money around. #### Records The dashboard lists every top-up with its transaction hash, every purchase with its tier or term, and usage per day, per network and per sub-user. The same data is available through [`GET /v1/usage`](https://proxshift.com/docs/api#get-v1-usage) and [`GET /v1/orders`](https://proxshift.com/docs/api#get-v1-orders). ### API reference (https://proxshift.com/docs/api) Everything the dashboard does, as JSON over HTTPS. Base URL `https://api.proxshift.com/v1`, Bearer authentication, cursor pagination. > Info: The contract on this page is final. The same contract is published as an [OpenAPI 3.1 document](https://proxshift.com/docs/openapi.json), generated from this page, for client generators and agent tooling. #### Conventions - **Base URL**: `https://api.proxshift.com/v1` - **Authentication**: `Authorization: Bearer TOKEN`. Tokens are created in the dashboard under **API tokens**; each can be revoked independently. `GET /v1/pricing` needs no token. - **Format**: JSON in and out, `Content-Type: application/json`, UTF-8. Timestamps are ISO 8601 in UTC. Money is a decimal string in USD; traffic is in bytes unless a field name says `_gb`. - **Pagination**: List endpoints take `limit` (default 50, max 200) and `cursor`, and return `next_cursor` (null on the last page). - **Idempotency**: Send an `Idempotency-Key` header on `POST /orders` and `POST /orders/{id}/renew`; a repeated key within 24 hours returns the original result instead of charging twice. - **Rate limit**: 120 requests per minute per token. `X-RateLimit-Remaining` on every response; `429` with `Retry-After` when exceeded. #### Errors Errors use standard status codes and a single JSON shape. `code` is stable and meant for your program; `message` is for humans and may change. ```json { "error": { "code": "insufficient_balance", "message": "This order costs 28.22 USD; the wallet holds 12.40 USD." } } ``` | Status | Codes | Meaning | | --- | --- | --- | | 400 | invalid_request, invalid_parameter | Malformed JSON or a field outside its allowed values; `message` names the field | | 401 | invalid_token | Missing, revoked or malformed Bearer token | | 402 | insufficient_balance | The wallet cannot cover the purchase | | 404 | not_found | Unknown id, or an object that belongs to another account | | 409 | conflict | The state does not allow the action, for example renewing an order that already ended | | 429 | rate_limited | Too many requests; wait `Retry-After` seconds | | 5xx | internal_error | Retry with backoff; nothing was charged if no `order` object was returned | #### Account and balance ##### GET /v1/account The account behind the token. Request: ```bash curl https://api.proxshift.com/v1/account -H "Authorization: Bearer TOKEN" ``` Response: ```json { "id": "acc_3f9k2m", "created_at": "2026-09-21T08:14:02Z", "whitelist_count": 2, "subuser_count": 3 } ``` ##### GET /v1/balance Wallet balance and traffic balances per pool network, in bytes and GB. Request: ```bash curl https://api.proxshift.com/v1/balance -H "Authorization: Bearer TOKEN" ``` Response: ```json { "wallet_usd": "142.60", "traffic": { "residential": { "bytes": 96636764160, "gb": 90.0 }, "mobile": { "bytes": 2147483648, "gb": 2.0 } } } ``` ##### GET /v1/usage Traffic consumed per day, filtered by network, order or sub-user. Pool networks report bytes billed; dedicated orders report bytes moved. | Field | In | Description | | --- | --- | --- | | from, to | query | Dates `YYYY-MM-DD`, inclusive, UTC. Default: the last 30 days | | network | query | `residential`, `mobile`, `isp`, `datacenter` (optional) | | order_id | query | Restrict to one dedicated order (optional) | | subuser_id | query | Restrict to one sub-user (optional) | Request: ```bash curl "https://api.proxshift.com/v1/usage?from=2026-09-01&to=2026-09-21&network=residential" \ -H "Authorization: Bearer TOKEN" ``` Response: ```json { "network": "residential", "days": [ { "date": "2026-09-20", "bytes": 5368709120, "requests": 184220 }, { "date": "2026-09-21", "bytes": 1073741824, "requests": 40118 } ], "total_bytes": 6442450944 } ``` #### Credentials, sub-users and whitelist ##### GET /v1/credentials The account's username and password for the shared gateways. Request: ```bash curl https://api.proxshift.com/v1/credentials -H "Authorization: Bearer TOKEN" ``` Response: ```json { "username": "u7f3a9c", "password": "kq2Lm8Pz1r", "hosts": { "residential": "res.proxshift.com", "mobile": "mob.proxshift.com" }, "ports": { "http": 9000, "socks5": 9001 } } ``` ##### POST /v1/credentials/rotate Generate a new password. The previous one keeps working for ten minutes. Request: ```bash curl -X POST https://api.proxshift.com/v1/credentials/rotate -H "Authorization: Bearer TOKEN" ``` Response: ```json { "username": "u7f3a9c", "password": "Xr4Nv7Qw2t", "previous_valid_until": "2026-09-21T09:24:00Z" } ``` ##### POST /v1/subusers Create a sub-user: an extra credential pair with its own traffic ceiling. `GET /v1/subusers` lists them; `PATCH /v1/subusers/{id}` changes the limit or disables it; `DELETE` removes it. | Field | In | Description | | --- | --- | --- | | label | body | Free text, shown in usage reports | | limit_gb | body | Ceiling in GB across pool networks, or `null` for no ceiling | | networks | body | Array of allowed pool networks, default `["residential","mobile"]` | Request: ```bash curl -X POST https://api.proxshift.com/v1/subusers \ -H "Authorization: Bearer TOKEN" -H "Content-Type: application/json" \ -d '{"label":"client-acme","limit_gb":50}' ``` Response: ```json { "id": "sub_9d2x", "label": "client-acme", "username": "u7f3a9c-acme", "password": "Pm3Kz8Rt5v", "limit_gb": 50, "used_gb": 0, "networks": ["residential", "mobile"], "enabled": true } ``` ##### GET /v1/whitelist Addresses allowed to connect without credentials. Request: ```bash curl https://api.proxshift.com/v1/whitelist -H "Authorization: Bearer TOKEN" ``` Response: ```json { "items": [ { "ip": "198.51.100.23", "label": "worker-1", "added_at": "2026-09-19T10:02:11Z" } ] } ``` ##### POST /v1/whitelist Add an IPv4 address (up to 50 per account). `DELETE /v1/whitelist/{ip}` removes one. Changes apply within a minute. | Field | In | Description | | --- | --- | --- | | ip | body | Public IPv4 address | | label | body | Optional free text | Request: ```bash curl -X POST https://api.proxshift.com/v1/whitelist \ -H "Authorization: Bearer TOKEN" -H "Content-Type: application/json" \ -d '{"ip":"198.51.100.23","label":"worker-1"}' ``` Response: ```json { "ip": "198.51.100.23", "label": "worker-1", "added_at": "2026-09-21T09:15:40Z" } ``` #### Pricing ##### GET /v1/pricing (public, no token) The published price tables: per-GB ladders, dedicated terms, location zones and volume discounts. The same figures as the website; no token required. Request: ```bash curl https://api.proxshift.com/v1/pricing ``` Response: ```json { "currency": "USD", "residential": { "unit": "GB", "tiers": [ { "min_gb": 1, "price": "2.45" }, { "min_gb": 100, "price": "1.54" } ] }, "isp": { "terms": [ { "days": 30, "per_month": "1.12" }, { "days": 90, "per_month": "0.99" } ], "zones": { "a": { "label": "United States", "mult": 1.0, "codes": ["US"] } }, "volume_discounts": [ { "min_ips": 10, "pct": 5 } ] } } ``` #### Orders and proxy lists ##### POST /v1/orders Buy traffic on a pool network, or rent dedicated addresses or devices. The wallet is charged on success; send an `Idempotency-Key`. | Field | In | Description | | --- | --- | --- | | network | body | `residential`, `mobile`, `isp`, `datacenter`, `mobile_device` | | gb | body | Pool networks: GB to buy (the tier is derived from this amount) | | country | body | Dedicated: ISO country code of the addresses | | city | body | Dedicated: city value where offered (optional) | | carrier_asn | body | Mobile devices: preferred carrier AS number (optional) | | quantity | body | Dedicated: number of addresses or devices | | term_days | body | Dedicated: `1`, `30`, `60` or `90` (`1` only for ISP and mobile devices) | Request: ```bash curl -X POST https://api.proxshift.com/v1/orders \ -H "Authorization: Bearer TOKEN" -H "Content-Type: application/json" \ -H "Idempotency-Key: 5d1c7e2a-order-de-isp" \ -d '{"network":"isp","country":"DE","quantity":10,"term_days":90}' ``` Response: ```json { "id": "ord_7hq4", "network": "isp", "country": "DE", "quantity": 10, "term_days": 90, "starts_at": "2026-09-21T09:20:00Z", "ends_at": "2026-12-20T09:20:00Z", "total_usd": "33.86", "status": "provisioning" } ``` ##### GET /v1/orders All orders, newest first. `GET /v1/orders/{id}` returns one, including its addresses once provisioned. | Field | In | Description | | --- | --- | --- | | status | query | `provisioning`, `active`, `ended` (optional) | | network | query | Filter by network (optional) | Request: ```bash curl "https://api.proxshift.com/v1/orders?status=active" -H "Authorization: Bearer TOKEN" ``` Response: ```json { "items": [ { "id": "ord_7hq4", "network": "isp", "country": "DE", "quantity": 10, "status": "active", "ends_at": "2026-12-20T09:20:00Z" } ], "next_cursor": null } ``` ##### POST /v1/orders/{id}/renew Extend a dedicated order by another term and keep the same addresses. Allowed while the order is active. | Field | In | Description | | --- | --- | --- | | term_days | body | `30`, `60` or `90`; default: the order's current term | Request: ```bash curl -X POST https://api.proxshift.com/v1/orders/ord_7hq4/renew \ -H "Authorization: Bearer TOKEN" -H "Content-Type: application/json" \ -H "Idempotency-Key: renew-ord_7hq4-2026-12" -d '{"term_days":90}' ``` Response: ```json { "id": "ord_7hq4", "ends_at": "2027-03-20T09:20:00Z", "total_usd": "33.86", "status": "active" } ``` ##### GET /v1/proxies Your dedicated addresses across orders. `format=txt` returns plain `ip:port:user:pass` lines, one per address, ready for any tool. | Field | In | Description | | --- | --- | --- | | network | query | `isp`, `datacenter`, `mobile_device` (optional) | | order_id | query | One order only (optional) | | format | query | `json` (default) or `txt` | Request: ```bash curl "https://api.proxshift.com/v1/proxies?network=isp&format=txt" -H "Authorization: Bearer TOKEN" ``` Response: ```json 203.0.113.42:8000:u7f3a9c:kq2Lm8Pz1r 203.0.113.57:8000:u7f3a9c:kq2Lm8Pz1r ``` #### Devices ##### GET /v1/devices Your dedicated mobile devices with their current IP, carrier and rotation settings. `GET /v1/devices/{id}` returns one. Request: ```bash curl https://api.proxshift.com/v1/devices -H "Authorization: Bearer TOKEN" ``` Response: ```json { "items": [ { "id": "dev_8k2m", "order_id": "ord_2ps9", "country": "US", "carrier": "T-Mobile", "endpoint": { "ip": "198.51.100.9", "http": 8000, "socks5": 8001 }, "current_ip": "172.58.19.204", "rotate_every_minutes": null, "last_rotated_at": "2026-09-21T08:50:12Z", "ends_at": "2026-11-20T09:20:00Z" } ], "next_cursor": null } ``` ##### POST /v1/devices/{id}/rotate Ask the carrier for a new IP now. Returns when the device is back online with its new address; connections in flight are dropped. The dashboard's rotation link calls the same operation with a signed key instead of a token. Request: ```bash curl -X POST https://api.proxshift.com/v1/devices/dev_8k2m/rotate -H "Authorization: Bearer TOKEN" ``` Response: ```json { "id": "dev_8k2m", "current_ip": "172.58.22.77", "rotated_at": "2026-09-21T09:31:05Z" } ``` ##### PATCH /v1/devices/{id} Change the rotation timer. `null` disables it. | Field | In | Description | | --- | --- | --- | | rotate_every_minutes | body | Integer from 2 to 1440, or `null` | Request: ```bash curl -X PATCH https://api.proxshift.com/v1/devices/dev_8k2m \ -H "Authorization: Bearer TOKEN" -H "Content-Type: application/json" \ -d '{"rotate_every_minutes":10}' ``` Response: ```json { "id": "dev_8k2m", "rotate_every_minutes": 10 } ``` ### Limits & fair use (https://proxshift.com/docs/limits) Short page on purpose. The technical limits fit in one table; the rules of use fit in one list. #### Technical limits | Item | Limit | | --- | --- | | Concurrent connections | Unlimited, on every network | | Requests per second | No limit on the gateway; the target sets the pace | | Concurrent sticky sessions | Unlimited | | Sticky session lifetime | 1 minute to 24 hours, default 10 minutes | | Whitelisted addresses | 50 per account, IPv4 | | Sub-users | Unlimited | | Idle connection to the gateway | Closed after 60 seconds without traffic | | Transfer duration | No limit while data flows | | Destination ports | Any TCP port except 25 | | UDP, IPv6 targets, inbound connections | Not supported | | API | 120 requests per minute per token | #### Traffic by network | Network | Traffic model | | --- | --- | | Residential | Metered per GB, both directions, bought in advance, never expires | | Mobile, rotating | Metered per GB, same rules as residential, separate balance | | ISP | Unlimited and unmetered | | Datacenter | 100 GB per IP per month, pooled across the order; speed reduced when the pool is exhausted, never cut | | Mobile, dedicated device | Unlimited and unmetered | "Unlimited" means unmetered: we do not count the bytes and we do not throttle. Dedicated addresses are yours alone, so the only capacity you compete with is your own. #### Acceptable use The network is for collecting and verifying public information, running your own accounts and properties, and testing what you are entitled to test. The [acceptable use policy](https://proxshift.com/legal/acceptable-use) is the binding text; in short, the following ends an account: - Attacks of any kind: denial of service, brute force, credential stuffing, exploitation of vulnerabilities you have no authorization to test. - Fraud, including payment fraud, fake engagement sold to third parties, and impersonation. - Unauthorized access to systems, accounts or data. - Spam and unsolicited bulk messaging (this is also why port 25 is closed). - Anything illegal where you operate or where the target operates, and any content involving the abuse of minors. - Collecting personal data without a lawful basis, or reselling access to the network without agreement. Abuse reports are investigated and acted on; where the law requires, we cooperate with the authorities. Residential exits belong to real people who opted in, and we protect them first. #### Good citizenship - Pace requests per domain and back off on `429`. The absence of a limit on our side is not an invitation to hammer a target. - Respect `robots.txt` where it applies to what you do, and the target's terms where they bind you. - Prefer the network that fits: datacenter for open sources, residential and mobile only where the target requires them. ### Documentation FAQ **Where do I find my credentials?** In the dashboard under Credentials, once the account is funded: one username and one password for the residential and mobile gateways. Dedicated ISP, datacenter and mobile-device orders come with their own ip:port:user:pass lines. The same data is returned by GET /v1/credentials and GET /v1/proxies. **Do I need different credentials per network?** No. The shared gateways res.proxshift.com and mob.proxshift.com take the same username and password; only the hostname changes. Dedicated addresses each have their own pair, printed in your list, and the IP whitelist covers every endpoint at once. **Is there an SDK to install?** No, and none is needed. ProxShift proxies are standard HTTP(S) and SOCKS5 proxies, so every language, library, browser and tool that can use a proxy already works. The code examples page covers the clients people use most. **Can I use the same username parameters on mobile?** Yes. -cc-, -asn-, -sid- and -ttl- behave identically on mob.proxshift.com; -state- and -city- exist for the residential pool. On the mobile pool -asn- is how you choose a carrier. **How is traffic measured on the pool networks?** Every byte that crosses the gateway in both directions counts: request and response, headers and TLS records included. Connections that fail before reaching the target are not billed. ISP proxies and dedicated mobile devices are unmetered; datacenter orders carry a monthly pool. **What does testing cost?** A top-up of $20, which stays on your balance until you spend it. Buy a few GB on residential, or rent a single ISP address or a mobile device for 24 hours, run the recipe from the quickstart against your real target and scale from there. ## Use cases ### Proxies for web scraping (https://proxshift.com/use-cases/web-scraping) A crawler from one address is trivial to spot: hundreds of requests a minute from a hosting range, no browser history, the same fingerprint on every hit. Targets answer with rate limits, CAPTCHAs, empty pages or silent bans. A residential pool turns that stream into thousands of ordinary visitors from the countries you need, so the data you collect is the data a real user would see. Recommended network: Residential proxies. - Residential proxies (Recommended): Rotation on every request across real households defeats rate limits and bot scores. City and ASN targeting reproduce what local users see. Per GB, never expires. - Datacenter proxies (Good fit): Cheapest per request for targets that do not fingerprint hosting ranges: public APIs, sitemaps, your own properties, low-protection catalogues. - ISP proxies (Possible): Only when the crawl needs a login that must stay on one address; otherwise you pay for stability you do not use. - Mobile proxies (Possible): Overkill for most collection, but the fallback for targets that block everything else. Recipe: - Rotation: Rotating: omit -sid- so every request leaves from a new exit. - Targeting: -cc- for the market you scrape; add -city- when prices or listings are local. - Concurrency: Unlimited threads on the gateway; keep per-domain rates polite, the pool is not a licence to hammer. - Protocol: HTTP(S) on port 9000 for most clients; SOCKS5 on 9001 for non-HTTP tooling. - Retries: On a 403 or CAPTCHA, retry once; the next request is already a different IP. **Residential or datacenter for scraping?** Start with datacenter if the target does not challenge you: it is the cheapest per request. The moment you see CAPTCHAs, 403s or degraded content, move that target to residential; the per-GB price buys the success rate. **How much traffic does scraping use?** HTML alone is usually 100 to 500 KB per page. Half a million pages at 350 KB is about 170 GB, which costs around $262 on the residential ladder. Headless browsers that load images can multiply that by five; block them. **Do you allow scraping?** Collecting publicly available data is allowed. Attacking a site, bypassing authentication, or harvesting personal data without a legal basis is not, and the acceptable use policy is enforced. **Can I rotate per request and keep a session when I need one?** Yes, on the same account. Omit the session parameters for rotation; add -sid- and -ttl- on the requests that must share an IP. **What success rate should I expect?** It depends on the target far more than on the pool. Well-behaved crawlers on residential exits typically see the vast majority of requests succeed; the rest is retried on a fresh IP at no extra cost beyond the bytes. ### Proxies for price monitoring (https://proxshift.com/use-cases/price-monitoring) Retailers price by country, by region, sometimes by city, and serve different stock and shipping rules to different visitors. A checker running from one datacenter sees one version, often a defensive one. Residential exits in each market return the real shelf: the price a local pays, the stock a local can order, the promotion a local is shown. Recommended network: Residential proxies. - Residential proxies (Recommended): Country and city targeting on real households returns the localized price and stock. Rotation keeps daily sweeps of large catalogues undetected. - ISP proxies (Good fit): For a small set of retailers checked frequently from one consistent location, a static ISP IP per market is cheaper than per-GB traffic. - Datacenter proxies (Possible): Retail sites are among the first to block hosting ranges or serve them different prices; use only for your own storefronts. - Mobile proxies (Possible): Useful only for app-only prices or mobile-specific promotions. Recipe: - Rotation: Rotating for catalogue sweeps; sticky (-ttl-5m) when a price sits behind a cart or postcode step. - Targeting: -cc- per market and -city- where delivery pricing is local; keep one exit per basket. - Schedule: Spread sweeps over the day; a burst at 03:00 from one country is a signature. - Currency: Localized pages return local currency; store the exit country with each price. **Why do I see different prices than my checker?** Because you are a different visitor: another country, another device class, another history. Residential exits in the market you monitor show the price that market actually pays. **How many GB does price monitoring need?** A product page is 200 to 400 KB of HTML. Two hundred thousand checks a month at 300 KB is roughly 60 GB, about $105 on the residential ladder. **Should I use ISP proxies instead?** If you check a handful of retailers many times a day from fixed locations, a static ISP IP per market is cheaper and simpler. For wide catalogues across many countries, residential wins. **Can I monitor marketplaces like Amazon or Mercado Libre?** Yes, from the country of each marketplace. Large marketplaces score visitors aggressively, so residential rotation with polite per-domain rates is the reliable setup. ### Proxies for SEO and SERP tracking (https://proxshift.com/use-cases/seo-serp-tracking) Search engines personalize by location, history and device, and they throttle repeated queries from one address within minutes. Rank data is only meaningful when each query comes from a clean, local visitor. Residential exits in the target city give exactly that, one query at a time, at any volume. Recommended network: Residential proxies. - Residential proxies (Recommended): Clean local IPs for every query; city targeting for local SEO; rotation defeats the per-IP query throttle. - Mobile proxies (Recommended): Mobile results differ from desktop and drive most traffic; carrier IPs return the true mobile SERP. - ISP proxies (Good fit): Fine for low-volume, single-market tracking where a stable address is acceptable. - Datacenter proxies (Possible): Hosting ranges are throttled and challenged by search engines within a few queries. Recipe: - Rotation: Rotating, one query per exit; no session needed. - Targeting: -cc- plus -city- for local packs; add the engine's own location parameters as well. - Device: Send a mobile user agent through mob.proxshift.com for mobile rankings, a desktop one through res.proxshift.com. - Language: Set Accept-Language to the market's language; the exit alone does not change the interface language. **Do I need city targeting for SEO?** For local queries, yes: a "plumber near me" result in Lyon differs from Paris. For national keywords, country targeting is enough. **How much traffic per query?** A result page is around 100 to 150 KB of HTML. Three hundred thousand queries at 120 KB is about 35 GB, roughly $64 a month on the residential ladder. **Can I use SOCKS5 with my rank tracker?** Yes, on port 9001 with the same username parameters. Most trackers accept an HTTP proxy on port 9000 directly. **Why not datacenter proxies for SERP data?** Search engines throttle hosting ranges after a handful of queries and serve CAPTCHAs. The per-GB cost of residential is lower than the retries and gaps you would pay for otherwise. ### Proxies for ad verification (https://proxshift.com/use-cases/ad-verification) Ad networks target by geography, device and connection type, and fraudsters serve clean creatives to anything that looks like a verifier. To see the placement a real user in Madrid on Movistar gets, you have to be that user: a residential or mobile exit in Madrid, with the matching device profile. Recommended network: Residential proxies. - Residential proxies (Recommended): Household exits by country and city reproduce desktop and mobile-web placements as the audience sees them. - Mobile proxies (Recommended): In-app and carrier-targeted campaigns require a real carrier IP; dedicated devices let you check one carrier repeatedly. - ISP proxies (Possible): Stable IPs are recognizable over time; only for verifying your own publisher inventory. - Datacenter proxies (Not suited): Ad networks classify hosting ranges instantly and serve nothing, or a decoy. Recipe: - Rotation: Rotating for coverage across many households; sticky when a placement depends on a session. - Targeting: -cc- and -city- to match the campaign geo; -asn- to check a specific provider; carrier selection on mobile. - Device: Pair the exit with a matching user agent and viewport; a mobile IP with a desktop browser is a red flag. - Evidence: Capture screenshot, final URL and redirect chain with the exit details for every check. **Residential or mobile for ad verification?** Residential for desktop and mobile-web placements; mobile for in-app inventory and carrier-targeted campaigns. Many teams run both. **How much traffic does a verification load use?** A full page with creatives is 2 to 4 MB. Twenty thousand loads at 2.5 MB is about 50 GB, roughly $87 on the residential ladder. **Can I verify on a specific carrier?** Yes: pick the country and carrier on the mobile pool, or rent a dedicated device on that carrier for repeated checks. **Can I use headless browsers?** Yes. Authenticate the proxy in the browser and keep a sticky session for the page load so the HTML and the ad calls share one exit. ### Proxies for social media management (https://proxshift.com/use-cases/social-media-management) Platforms tie an account to a location, a device and a connection type, and they react to changes: a login from a new country or from a hosting range means a verification loop, a shadow limit or a ban. An account that always appears from the same city, on a residential or mobile address, is simply a normal user. Recommended network: Mobile proxies. - Mobile proxies (Recommended): Platforms are mobile-first and treat carrier IPs as their most trusted traffic; a dedicated device gives one account one phone-like footprint. - ISP proxies (Recommended): A static residential IP per account, unlimited traffic, the same address for months: the cheapest stable option for many accounts. - Residential proxies (Good fit): Sticky sessions up to 24 hours work for scheduled posting; the daily IP change is acceptable on some platforms, not all. - Datacenter proxies (Not suited): Hosting ranges are flagged on signup and login; do not use for accounts. Recipe: - Network: Dedicated mobile device or ISP IP per account, in the account's home country. - Consistency: Never move an account between IPs or countries; one account, one address, one browser profile. - Rotation: On a dedicated device, rotate the IP only when the platform would expect it (a new day, a new session), not per request. - Isolation: One proxy per account in your browser or automation tool; shared exits link accounts together. **Mobile or ISP for social media?** Mobile when the platform is mobile-first or the account is valuable: carrier IPs get the most tolerance. ISP when you manage many accounts and need a cheap, static address each. **Can several accounts share one proxy?** They can, and the platform will notice. Give each account its own dedicated IP or device. **How much does a dedicated setup cost?** A US ISP IP is $1.12 for 30 days, $0.99 per month on 90 days. A dedicated US mobile device is $69 for 30 days, $62.10 per month on 90 days; cheaper zones start at $34.50. **Is this allowed?** Managing your own or your clients' accounts is a normal use. Creating accounts to spam, defraud or impersonate is not, and the acceptable use policy applies. ### Proxies for e-commerce automation (https://proxshift.com/use-cases/ecommerce-automation) Checkouts and limited releases sit behind the strictest bot protection on the web, and they judge the IP first. Hosting ranges are refused outright; a residential address that changes mid-checkout fails the session check. What works is a trusted, stable address in the retailer's home market for the whole flow, and enough of them to run in parallel. Recommended network: ISP proxies. - ISP proxies (Recommended): Static residential-registered IPs, one per task, stay consistent from product page to payment with datacenter speed and unlimited traffic. - Residential proxies (Good fit): Sticky sessions hold one household for the flow; good for monitoring and moderate-protection stores. - Mobile proxies (Good fit): Carrier IPs pass the harshest checkouts; dedicated devices for the accounts that matter most. - Datacenter proxies (Not suited): Refused at the door by most retailers. Recipe: - Network: ISP IPs in the retailer's country, one per checkout task; mobile devices for the toughest targets. - Session: On residential, -sid- with -ttl-30m so the whole flow shares one exit. - Speed: Wired ISP uplinks matter on drops where seconds decide; residential latency varies with the household. - Monitoring: Rotate residential exits for stock and price polling, keep static IPs for checkout only. **ISP or residential for checkout?** ISP for anything guarded: stable, fast, residential-registered. Residential sticky sessions for stores with lighter protection or for monitoring. **How many IPs do I need?** One per parallel task. Ten tasks, ten IPs: $11.20 for 30 days in the United States, less on longer terms and larger orders. **Are the IPs clean?** Dedicated ISP and datacenter IPs are yours alone during the term and are checked against blocklists before they enter your order. What you do with them afterwards is the history they carry. **Is this allowed?** Buying goods, monitoring stock and running your own marketplace operations are normal uses. Fraud, stolen payment data and account takeover are not, and the acceptable use policy is enforced. ### Proxies for brand protection (https://proxshift.com/use-cases/brand-protection) Counterfeiters and phishers cloak: they show a clean page to known security scanners and hosting ranges, and the real listing to shoppers in the target market. Finding what your customers see means looking from where they are, on the networks they use, at the times they browse. Recommended network: Residential proxies. - Residential proxies (Recommended): Household exits in every market defeat geo-cloaking and let you sweep marketplaces, social platforms and classifieds at scale. - Mobile proxies (Good fit): Scams targeting mobile users (SMS phishing, app-store clones) only reveal themselves to carrier traffic. - ISP proxies (Possible): For monitoring a fixed set of known infringing domains from one location. - Datacenter proxies (Not suited): Cloaked sites serve hosting ranges a decoy; useless for detection. Recipe: - Rotation: Rotating sweeps across marketplaces; sticky sessions to walk through a seller's listings. - Targeting: -cc- for each market you sell in; -city- where local classifieds matter. - Evidence: Screenshot, HTML, headers and exit details together; takedowns need proof of what was shown to whom. - Cadence: Sweep daily for high-value marks; infringing listings are short-lived by design. **Why do infringing pages look clean from the office?** Cloaking: the page checks your IP and shows a harmless version to hosting ranges and security vendors. A household exit in the target market gets the real one. **Which network for phishing detection?** Residential for web and marketplace sweeps; mobile for SMS-driven scams and app clones, which often serve carrier traffic only. **How much traffic does a sweep use?** Listing pages are 300 to 500 KB of HTML. One hundred thousand listings at 400 KB is about 40 GB, roughly $70 a month on the residential ladder. **Can I use the evidence in takedowns?** You own what you collect. Store the raw page with exit metadata; most platforms and registrars accept it as proof of what was served. ### Proxies for travel fare aggregation (https://proxshift.com/use-cases/travel-fare-aggregation) Airlines and OTAs price by point of sale and defend their booking engines harder than almost any other industry: hosting ranges are blocked, repeated searches from one address are throttled, and some carriers quote higher fares to traffic they distrust. Accurate aggregation needs a fresh local visitor for every search. Recommended network: Residential proxies. - Residential proxies (Recommended): Rotating household exits per point-of-sale country return the local fare and pass booking-engine defences at volume. - Mobile proxies (Good fit): App-only fares and mobile promotions exist; carrier exits reveal them. - ISP proxies (Possible): A few static IPs per market for low-volume monitoring of specific routes. - Datacenter proxies (Not suited): Blocked or served inflated fares by most booking engines. Recipe: - Rotation: Rotating: one search, one exit; hold a session (-ttl-10m) only when walking from results into a fare-rules page. - Targeting: -cc- equals the point of sale; store it with each fare, currency follows. - Pacing: Booking engines are heavy; pace per route and cache static content, you pay per GB. - Headers: Match Accept-Language and currency parameters to the exit country. **Why are fares different from my own search?** Point of sale, currency and trust level all change the quote. Residential exits in the target country return the fare that country is offered. **How much traffic does fare aggregation use?** Results pages are heavy, often 0.5 to 2 MB. One hundred fifty thousand searches at 900 KB is about 135 GB, around $208 on the residential ladder; fetching fare endpoints directly can cut that by half. **Can I use sticky sessions for multi-step searches?** Yes: add -sid- and -ttl-10m so results, fare rules and seat maps come from one household. **Is aggregation allowed?** Collecting publicly displayed fares is a common, legitimate use. Automated booking, inventory hoarding or bypassing access controls is not. ### Proxies for app and QA testing (https://proxshift.com/use-cases/app-testing) Your app behaves differently in Jakarta on a 4G connection than in the office on fibre: other CDN edge, other payment methods, other content rules, other latency. Emulators and VPN endpoints in datacenters do not reproduce that. Real residential and mobile exits in each market do, repeatably, from your CI pipeline. Recommended network: Residential proxies. - Residential proxies (Recommended): Household exits by country and city reproduce the real user's geo-gating, content and CDN routing. - Mobile proxies (Recommended): Carrier IPs test mobile-only flows, operator billing, app-store availability and in-app placements. - Datacenter proxies (Good fit): Fixed egress IPs you can whitelist for staging and load generation at scale. - ISP proxies (Possible): When a test account must keep one address across a long regression run. Recipe: - Rotation: Sticky sessions per test run (-ttl-1h) so a scenario stays on one exit; rotate between runs. - Targeting: -cc- and -city- per market under test; carrier selection for mobile-specific checks. - Whitelisting: Datacenter IPs for staging environments that only accept known addresses. - Assertions: Assert on what changes by location: currency, payment methods, legal text, CDN edge, media availability. **Residential or datacenter for QA?** Residential and mobile to see what users see; datacenter for fixed, whitelistable egress and load. Most pipelines use both. **How much traffic does a test run use?** A full scenario with assets is 3 to 10 MB. Five thousand runs a month at 6 MB is about 30 GB, roughly $55 on the residential ladder. **Can I keep one IP for the whole test?** Yes: a session ID with -ttl-1h holds the exit for the run, and a replacement in the same location is assigned if it drops. **Can I test app-store availability per country?** Yes, from a mobile exit in that country; store fronts and availability follow the carrier IP. ### Proxies for market research and data collection (https://proxshift.com/use-cases/market-research) Research datasets are only as good as their coverage: a job board seen from one country, a review site that hides half its pages from foreign visitors, a real-estate portal that throttles after a hundred pages. Country-by-country residential collection gives complete, comparable data; datacenter exits handle the sources that do not care who is asking. Recommended network: Residential proxies. - Residential proxies (Recommended): Complete local coverage of protected or geo-gated sources, one market at a time, with rotation for volume. - Datacenter proxies (Recommended): Bulk collection from open sources, public APIs and archives at the lowest cost per request. - ISP proxies (Possible): For sources that require a stable authenticated session over long crawls. - Mobile proxies (Possible): Only for mobile-exclusive sources and app content. Recipe: - Split by source: Datacenter for open sources, residential for guarded or geo-gated ones; one account, both networks. - Targeting: -cc- per market; collect each country from inside it for comparable samples. - Rotation: Rotating for breadth; sticky when pagination depends on a session cookie. - Storage: Keep raw HTML with exit metadata; re-parsing later is cheaper than re-crawling. **Residential or datacenter for datasets?** Both: datacenter for open sources at $0.80 per IP with 100 GB pooled each month, residential for guarded or geo-gated ones per GB. Route each source to the cheapest network that succeeds. **How much does a two-million-document crawl cost?** At 250 KB per document that is about 500 GB. On residential the 500 GB tier is $1.19 per GB, about $595; on datacenter, five IPs pool 500 GB a month for around $4. **Can I collect data for AI training?** Collecting public data is allowed within the acceptable use policy and the law that applies to you and the source. Personal data, paywalled content and sites that prohibit it are your responsibility to exclude. **Do you cap concurrency?** No. Unlimited threads on every network; per-domain politeness is on you. ## Guides ### How to use proxies with Python requests, httpx and aiohttp (https://proxshift.com/guides/python-requests-httpx) Three lines of configuration per library, then the same username syntax everywhere: country, city and session live in the proxy URL, so one gateway serves every job. #### The proxy URL Every Python HTTP library takes a proxy as a URL. With ProxShift the URL carries your credentials and the [targeting parameters](https://proxshift.com/docs/username-parameters) in the username; the hostname is the gateway and the port picks the protocol. ```text # Rotating: a new United States household on every new connection http://USER-cc-us:PASS@res.proxshift.com:9000 # Sticky: one Berlin household held for 30 minutes under the id "job42" http://USER-cc-de-city-berlin-sid-job42-ttl-30m:PASS@res.proxshift.com:9000 # SOCKS5 with remote DNS (socks5h), same parameters socks5h://USER-cc-us:PASS@res.proxshift.com:9001 ``` #### requests Pass the same URL for `http` and `https`; requests uses CONNECT for HTTPS destinations automatically. A `Session` reuses connections, which keeps you on the same exit until the connection closes; use one `Session` per sticky job and plain `requests.get` calls when you want a fresh exit per request. ```python import requests PROXY = "http://USER-cc-us:PASS@res.proxshift.com:9000" proxies = {"http": PROXY, "https": PROXY} # One request, one exit r = requests.get("https://api.ipify.org", proxies=proxies, timeout=30) print(r.text) # A sticky flow: same exit for every request of this session sticky = "http://USER-cc-de-city-berlin-sid-cart42-ttl-15m:PASS@res.proxshift.com:9000" s = requests.Session() s.proxies = {"http": sticky, "https": sticky} s.get("https://example.com/product/1", timeout=30) s.post("https://example.com/cart", json={"id": 1}, timeout=30) ``` > Tip: For SOCKS5 install the extra: `pip install \"requests[socks]\"`, then use `socks5h://` so DNS is resolved at the exit. #### httpx httpx takes a single `proxy=` argument (older versions: `proxies=`). It supports HTTP/2 to the destination through the CONNECT tunnel and works the same way in async code. ```python import httpx PROXY = "http://USER-cc-us:PASS@res.proxshift.com:9000" with httpx.Client(proxy=PROXY, timeout=30) as client: print(client.get("https://api.ipify.org").text) # async, one sticky exit per task import asyncio async def fetch(sid: str, url: str) -> str: proxy = f"http://USER-cc-us-sid-{sid}-ttl-10m:PASS@res.proxshift.com:9000" async with httpx.AsyncClient(proxy=proxy, timeout=30) as client: return (await client.get(url)).text asyncio.run(fetch("task1", "https://api.ipify.org")) ``` #### aiohttp aiohttp takes the proxy per request or per session and speaks HTTP proxies natively; SOCKS5 needs the `aiohttp-socks` connector. ```python import aiohttp, asyncio PROXY = "http://USER-cc-us:PASS@res.proxshift.com:9000" async def main(): async with aiohttp.ClientSession() as session: async with session.get("https://api.ipify.org", proxy=PROXY, timeout=aiohttp.ClientTimeout(total=30)) as r: print(await r.text()) asyncio.run(main()) ``` #### Rotation, keep-alive and retries - A new TCP connection means a new exit. `requests.get` without a `Session` opens one per call; a `Session` or an httpx `Client` keeps connections alive and therefore keeps the exit until the pool recycles it. - Force a fresh exit inside a session by changing the `-sid-` value; force one per request by sending `Connection: close`. - Retry once on 403, 429 and connection errors: on a rotating gateway the retry is a different visitor. Never retry across exits in the middle of a sticky flow. - Set timeouts to the exit type: 15 s connect and 45 s read for residential, more for mobile. #### Saving gigabytes Residential traffic is billed per GB in both directions. Ask for compressed responses (`Accept-Encoding: gzip, br` is on by default in these libraries), prefer JSON endpoints to HTML, and never download images, fonts or media unless they are the data. A 350 KB page is cheap; a 4 MB page with assets is not. ### How to use proxies in Node.js with fetch, undici, axios and got (https://proxshift.com/guides/nodejs-fetch-undici-axios) Node has no global proxy setting by default. Each client takes an agent or a dispatcher; once you know which one, the ProxShift URL does the rest. #### Built-in fetch and undici Node's global `fetch` is undici. Give it a `ProxyAgent` per request with the `dispatcher` option, or set it globally once with `setGlobalDispatcher`. ```javascript import { fetch, ProxyAgent, setGlobalDispatcher } from "undici"; const proxy = new ProxyAgent("http://USER-cc-us:PASS@res.proxshift.com:9000"); // Per request const res = await fetch("https://api.ipify.org", { dispatcher: proxy }); console.log(await res.text()); // Or globally, for every fetch in the process setGlobalDispatcher(proxy); ``` A `ProxyAgent` pools connections, so consecutive requests may reuse one connection and therefore one exit. For a fresh exit per request create the agent with `pipelining: 0` and `connections: 1`, or simply use a different `-sid-` per logical session. #### axios axios's own `proxy` option does not tunnel HTTPS reliably; the standard approach is an agent from `https-proxy-agent` and `proxy: false`. ```javascript import axios from "axios"; import { HttpsProxyAgent } from "https-proxy-agent"; const agent = new HttpsProxyAgent("http://USER-cc-de-city-berlin-sid-cart42-ttl-15m:PASS@res.proxshift.com:9000"); const client = axios.create({ httpsAgent: agent, httpAgent: agent, proxy: false, timeout: 30000 }); const { data } = await client.get("https://api.ipify.org"); console.log(data); ``` #### got ```javascript import got from "got"; import { HttpsProxyAgent } from "https-proxy-agent"; const agent = new HttpsProxyAgent("http://USER-cc-us:PASS@res.proxshift.com:9000"); const body = await got("https://api.ipify.org", { agent: { https: agent, http: agent }, timeout: { request: 30000 } }).text(); console.log(body); ``` #### SOCKS5 ```javascript import { SocksProxyAgent } from "socks-proxy-agent"; // socks5h resolves the destination at the exit const agent = new SocksProxyAgent("socks5h://USER-cc-us:PASS@res.proxshift.com:9001"); const res = await fetch("https://api.ipify.org", { dispatcher: undefined, agent }); // node-fetch style clients take `agent` ``` > Info: The built-in fetch does not accept `agent`; use undici's `ProxyAgent` for HTTP proxies, or a SOCKS-capable dispatcher such as `fetch-socks`. For most jobs the HTTP proxy on port 9000 is simpler. #### Environment variables undici does not read `HTTPS_PROXY` by default. Recent undici versions ship `EnvHttpProxyAgent`, which does; set it as the global dispatcher and the whole process, including third-party libraries built on fetch, goes through the proxy. ```javascript import { EnvHttpProxyAgent, setGlobalDispatcher } from "undici"; // HTTPS_PROXY=http://USER-cc-us:PASS@res.proxshift.com:9000 NO_PROXY=localhost node app.js setGlobalDispatcher(new EnvHttpProxyAgent()); ``` #### Concurrency and rotation - One `ProxyAgent` per sticky session (different `-sid-`), shared by all requests of that session. - For wide rotation, keep one agent but disable connection reuse, or run N agents with N session ids and round-robin them. - Watch `UND_ERR_SOCKET` and `ECONNRESET`: a residential exit went away; retry once, the next connection picks another. ### cURL through a proxy: every option that matters, with examples (https://proxshift.com/guides/curl-proxy-options) cURL is the fastest way to prove a proxy works and the reference every library imitates. Learn its five proxy flags and you can debug any client. #### The one-liner ```bash curl -x http://USER-cc-us:PASS@res.proxshift.com:9000 https://api.ipify.org ``` `-x` (or `--proxy`) takes the proxy URL with credentials embedded. cURL tunnels HTTPS destinations with CONNECT automatically, and asks the proxy to resolve the hostname. #### Flags worth knowing | Flag | Purpose | | --- | --- | | -x, --proxy URL | The proxy: scheme, host, port, optional credentials | | -U, --proxy-user user:pass | Credentials separately, useful when the password has special characters | | --proxy-basic | Force Basic proxy authentication (the default when a password is given) | | -v | Show the CONNECT exchange, proxy status codes and the response headers | | --noproxy '*' | Ignore proxy environment variables for this call | | -w '%{time_total}\n' | Print timing to compare exits | #### SOCKS5 and remote DNS ```bash # Hostname resolved at the exit (recommended) curl -x socks5h://USER-cc-de:PASS@res.proxshift.com:9001 https://api.ipify.org # Hostname resolved locally, then the IP is sent to the proxy (leaks the lookup) curl -x socks5://USER-cc-de:PASS@res.proxshift.com:9001 https://api.ipify.org ``` #### Environment variables Tools that shell out to cURL, and many others, honour `http_proxy`, `https_proxy` and `no_proxy`. Export them once for a session of work. ```bash export https_proxy="http://USER-cc-us:PASS@res.proxshift.com:9000" export http_proxy="$https_proxy" export no_proxy="localhost,127.0.0.1" curl https://api.ipify.org # proxied without -x ``` #### Reading a failure ```bash curl -v -x http://USER:WRONG@res.proxshift.com:9000 https://api.ipify.org 2>&1 | grep -E "CONNECT|HTTP/1.1 4|HTTP/1.1 5" # < HTTP/1.1 407 Proxy Authentication Required -> credentials # < HTTP/1.1 400 Bad Request -> a username parameter is wrong # < HTTP/1.1 502 Bad Gateway -> no exit for that location; widen it ``` A status on the CONNECT line comes from the gateway; a status after `Connection established` comes from the destination. The [errors page](https://proxshift.com/docs/errors) maps every gateway code. #### Rotating sessions in a loop ```bash for i in $(seq 1 5); do curl -s -x "http://USER-cc-us-sid-run$i-ttl-5m:PASS@res.proxshift.com:9000" https://api.ipify.org echo done # five different United States exits, each reusable for five minutes under its id ``` ### Proxies in Go and PHP: net/http Transport, x/net/proxy, cURL and Guzzle (https://proxshift.com/guides/go-and-php-proxies) Both languages give you the proxy at the transport layer, which is exactly where rotation and connection reuse are decided. Two idioms each, and you control the exit precisely. #### Go: http.Transport ```go package main import ( "fmt" "io" "net/http" "net/url" "time" ) func main() { proxyURL, _ := url.Parse("http://USER-cc-us:PASS@res.proxshift.com:9000") client := &http.Client{ Timeout: 45 * time.Second, Transport: &http.Transport{ Proxy: http.ProxyURL(proxyURL), DisableKeepAlives: true, // new connection = new exit on the rotating gateway }, } resp, err := client.Get("https://api.ipify.org") if err != nil { panic(err) } defer resp.Body.Close() body, _ := io.ReadAll(resp.Body) fmt.Println(string(body)) } ``` Leave `DisableKeepAlives` at its default (false) for sticky work: the transport reuses connections and therefore the exit. Use one `Transport` per session id when you run parallel sticky flows. #### Go: choosing the proxy per request ```go tr := &http.Transport{ Proxy: func(r *http.Request) (*url.URL, error) { sid := r.Header.Get("X-Session") // your own hint, never sent to the proxy r.Header.Del("X-Session") return url.Parse(fmt.Sprintf("http://USER-cc-de-sid-%s-ttl-10m:PASS@res.proxshift.com:9000", sid)) }, } ``` #### Go: SOCKS5 ```go import "golang.org/x/net/proxy" dialer, err := proxy.SOCKS5("tcp", "res.proxshift.com:9001", &proxy.Auth{User: "USER-cc-us", Password: "PASS"}, proxy.Direct) if err != nil { panic(err) } tr := &http.Transport{Dial: dialer.Dial} client := &http.Client{Transport: tr, Timeout: 45 * time.Second} ``` #### PHP: cURL ```php "http://res.proxshift.com:9000", CURLOPT_PROXYUSERPWD => "USER-cc-us:PASS", CURLOPT_RETURNTRANSFER => true, CURLOPT_CONNECTTIMEOUT => 15, CURLOPT_TIMEOUT => 45, CURLOPT_FORBID_REUSE => true, // new exit per call on the rotating gateway ]); echo curl_exec($ch); // SOCKS5 with remote DNS curl_setopt($ch, CURLOPT_PROXY, "res.proxshift.com:9001"); curl_setopt($ch, CURLOPT_PROXYTYPE, CURLPROXY_SOCKS5_HOSTNAME); ``` #### PHP: Guzzle ```php $sticky, 'timeout' => 45, 'connect_timeout' => 15]); $r = $client->get('https://api.ipify.org'); echo $r->getBody(); ``` #### Checklist - Reuse connections for sticky flows, disable reuse for wide rotation. - Timeouts scaled to the exit type; one retry on transport errors. - Never log the proxy URL: it contains the password. Log the session id instead. ### Using proxies with Playwright: one exit per browser or per context (https://proxshift.com/guides/playwright-proxy) Playwright takes the proxy at launch or per browser context, with credentials, so each context can be its own sticky session in its own country without restarting the browser. #### Launch-level proxy **Python** ```python from playwright.sync_api import sync_playwright with sync_playwright() as p: browser = p.chromium.launch(proxy={ "server": "http://res.proxshift.com:9000", "username": "USER-cc-us-sid-run1-ttl-30m", "password": "PASS", }) page = browser.new_page() page.goto("https://api.ipify.org") print(page.inner_text("body")) browser.close() ``` **Node.js** ```node import { chromium } from "playwright"; const browser = await chromium.launch({ proxy: { server: "http://res.proxshift.com:9000", username: "USER-cc-us-sid-run1-ttl-30m", password: "PASS" }, }); const page = await browser.newPage(); await page.goto("https://api.ipify.org"); console.log(await page.innerText("body")); await browser.close(); ``` A browser keeps connections alive, so use a sticky session id at launch: the whole browser then behaves like one visitor from one household for the lifetime you chose. #### Per-context proxies To run several countries or sessions in one browser, launch with a placeholder proxy and give each context its own. Chromium needs the launch-level proxy for per-context proxies to be honoured. **Python** ```python browser = p.chromium.launch(proxy={"server": "http://per-context"}) de = browser.new_context(proxy={"server": "http://res.proxshift.com:9000", "username": "USER-cc-de-city-berlin-sid-de1-ttl-30m", "password": "PASS"}) us = browser.new_context(proxy={"server": "http://res.proxshift.com:9000", "username": "USER-cc-us-state-tx-sid-us1-ttl-30m", "password": "PASS"}) ``` **Node.js** ```node const browser = await chromium.launch({ proxy: { server: "http://per-context" } }); const de = await browser.newContext({ proxy: { server: "http://res.proxshift.com:9000", username: "USER-cc-de-city-berlin-sid-de1-ttl-30m", password: "PASS" } }); const us = await browser.newContext({ proxy: { server: "http://res.proxshift.com:9000", username: "USER-cc-us-state-tx-sid-us1-ttl-30m", password: "PASS" } }); ``` #### Match the context to the exit Give each context the locale and time zone of its country, so IP, language and clock agree: `locale=\"de-DE\", timezone_id=\"Europe/Berlin\"` for the Berlin context. Mismatches are a stronger bot signal than the IP itself. #### Save gigabytes: block what you do not need **Python** ```python def block(route): if route.request.resource_type in {"image", "media", "font", "stylesheet"}: return route.abort() return route.continue_() page.route("**/*", block) ``` **Node.js** ```node await page.route("**/*", (route) => { const t = route.request().resourceType(); return ["image", "media", "font", "stylesheet"].includes(t) ? route.abort() : route.continue(); }); ``` A rendered page can weigh 3 to 5 MB; its HTML and API calls a few hundred kilobytes. On a per-GB network this single rule cuts the bill by 80 to 90 %. #### Verify and troubleshoot - Open an IP-echo service first and check the country; then look at a geolocation lookup for the city. - A `net::ERR_TUNNEL_CONNECTION_FAILED` or `ERR_PROXY_CONNECTION_FAILED` at launch means credentials or a parameter are wrong; test the same URL with cURL to read the gateway code. - WebRTC is disabled by default in Playwright contexts only if you block it; add `--disable-webrtc` style hardening or block STUN when privacy matters. ### Using proxies with Puppeteer and headless Chrome (https://proxshift.com/guides/puppeteer-proxy) Chrome takes the proxy as a launch flag and Puppeteer supplies the credentials per page. One browser is one exit; sticky sessions make that exit last. #### Launch with a proxy and authenticate ```javascript import puppeteer from "puppeteer"; const browser = await puppeteer.launch({ headless: true, args: ["--proxy-server=http://res.proxshift.com:9000", "--no-first-run"], }); const page = await browser.newPage(); await page.authenticate({ username: "USER-cc-us-sid-run1-ttl-30m", password: "PASS" }); await page.goto("https://api.ipify.org", { waitUntil: "domcontentloaded", timeout: 45000 }); console.log(await page.evaluate(() => document.body.innerText)); await browser.close(); ``` Call `page.authenticate` before the first navigation on every page you open; Chrome asks for proxy credentials per page. The username carries the country and the session id, so the whole browser stays on one household for the lifetime you set. #### One proxy per browser Chrome applies `--proxy-server` to the whole browser instance. For several countries or sessions run several browsers (cheap in headless mode), or use `puppeteer.launch` in a pool where each worker owns a session id. Libraries that promise per-page proxies insert a local forwarder; simpler to keep one browser per session. #### Block images, fonts and media ```javascript await page.setRequestInterception(true); page.on("request", (req) => { const t = req.resourceType(); if (["image", "media", "font", "stylesheet"].includes(t)) return req.abort(); req.continue(); }); ``` #### Consistency - Set `Accept-Language` and the time zone to the exit's country: `page.setExtraHTTPHeaders({\"Accept-Language\": \"de-DE,de;q=0.9\"})` and `page.emulateTimezone(\"Europe/Berlin\")`. - Disable WebRTC leaks with `--force-webrtc-ip-handling-policy=disable_non_proxied_udp` in the launch args. - Keep one browser per account; reuse its user data directory if the account should look like a returning device. #### Errors you will meet | Symptom | Cause | Fix | | --- | --- | --- | | net::ERR_TUNNEL_CONNECTION_FAILED | Gateway refused the CONNECT: credentials, parameter or no exit | Reproduce with cURL -v to read the gateway code | | net::ERR_PROXY_AUTH_UNSUPPORTED / prompts | authenticate() called after navigation | Call page.authenticate before goto | | Same IP in every browser | Same session id reused | Use a distinct -sid- per browser or omit it | | Very slow first load | Household exit plus heavy page | Block resources; raise timeout to 45 s | ### Using proxies with Selenium WebDriver (Chrome and Firefox) (https://proxshift.com/guides/selenium-proxy) The classic Selenium problem is authentication: browsers show a credentials prompt WebDriver cannot fill. Two clean answers: whitelist your server, or let Selenium Wire inject the credentials. #### Option 1: IP whitelisting (recommended for servers) Add your server's public IPv4 to the [whitelist](https://proxshift.com/docs/authentication) in the dashboard. Chrome then needs only the proxy address and never shows a prompt. The limit: a browser that is not challenged sends no username, so the gateway cannot read targeting parameters and uses the account's default pool. When each session needs its own country or sticky id, use Option 2. ```python from selenium import webdriver from selenium.webdriver.chrome.options import Options opts = Options() opts.add_argument("--proxy-server=http://res.proxshift.com:9000") opts.add_argument("--headless=new") driver = webdriver.Chrome(options=opts) driver.get("https://api.ipify.org") print(driver.find_element("tag name", "body").text) driver.quit() ``` #### Option 2: Selenium Wire (username, password and parameters) Selenium Wire runs a local proxy that adds the credentials for you, so the ProxShift URL with all its parameters works unchanged. ```python from seleniumwire import webdriver from selenium.webdriver.chrome.options import Options proxy = "http://USER-cc-de-city-berlin-sid-sel1-ttl-30m:PASS@res.proxshift.com:9000" sw_options = {"proxy": {"http": proxy, "https": proxy, "no_proxy": "localhost,127.0.0.1"}} opts = Options() opts.add_argument("--headless=new") driver = webdriver.Chrome(seleniumwire_options=sw_options, options=opts) driver.get("https://api.ipify.org") print(driver.find_element("tag name", "body").text) driver.quit() ``` > Warn: Selenium Wire intercepts TLS locally to add headers; it installs its own certificate in the browser it drives. Fine for automation, not for anything where certificate integrity matters. #### Firefox ```python from selenium import webdriver from selenium.webdriver.firefox.options import Options opts = Options() opts.set_preference("network.proxy.type", 1) opts.set_preference("network.proxy.http", "res.proxshift.com") opts.set_preference("network.proxy.http_port", 9000) opts.set_preference("network.proxy.ssl", "res.proxshift.com") opts.set_preference("network.proxy.ssl_port", 9000) opts.set_preference("media.peerconnection.enabled", False) # no WebRTC leak driver = webdriver.Firefox(options=opts) # whitelisted server, no prompt ``` #### Practical rules - One driver per session id; drivers keep connections alive, so the exit stays the same until the session lifetime ends. - Use `--headless=new` in Chrome; the old headless mode has a distinctive fingerprint. - Set the browser language and time zone to the exit's country; Selenium Wire can also rewrite `Accept-Language`. ### Rotating and sticky proxies in Scrapy with a downloader middleware (https://proxshift.com/guides/scrapy-rotating-proxies) Scrapy already knows how to speak to an authenticated HTTP proxy. A twenty-line middleware turns the ProxShift username syntax into per-request rotation and per-item sticky sessions. #### The simplest version Scrapy's built-in `HttpProxyMiddleware` reads `request.meta[\"proxy\"]` and handles credentials embedded in the URL. Set it in the spider and every request rotates on the gateway. ```python import scrapy PROXY = "http://USER-cc-us:PASS@res.proxshift.com:9000" class PricesSpider(scrapy.Spider): name = "prices" start_urls = ["https://example.com/catalog"] def start_requests(self): for url in self.start_urls: yield scrapy.Request(url, meta={"proxy": PROXY}) def parse(self, response): for href in response.css("a.product::attr(href)").getall(): yield response.follow(href, callback=self.parse_product, meta={"proxy": PROXY}) def parse_product(self, response): yield {"url": response.url, "price": response.css(".price::text").get()} ``` #### A middleware for sticky sessions per item ```python import hashlib class ProxShiftMiddleware: GATEWAY = "res.proxshift.com:9000" def __init__(self, user, password, country): self.user, self.password, self.country = user, password, country @classmethod def from_crawler(cls, crawler): s = crawler.settings return cls(s.get("PROXSHIFT_USER"), s.get("PROXSHIFT_PASS"), s.get("PROXSHIFT_COUNTRY", "us")) def process_request(self, request, spider): # Sticky when the request carries a session key (e.g. one per product flow), rotating otherwise key = request.meta.get("session_key") user = f"{self.user}-cc-{self.country}" if key: sid = hashlib.sha1(key.encode()).hexdigest()[:12] user += f"-sid-{sid}-ttl-10m" request.meta["proxy"] = f"http://{user}:{self.password}@{self.GATEWAY}" ``` ```python DOWNLOADER_MIDDLEWARES = { "myproject.middlewares.ProxShiftMiddleware": 350, # before HttpProxyMiddleware (750) } PROXSHIFT_USER = "USER" PROXSHIFT_PASS = "PASS" PROXSHIFT_COUNTRY = "de" CONCURRENT_REQUESTS = 32 CONCURRENT_REQUESTS_PER_DOMAIN = 8 AUTOTHROTTLE_ENABLED = True AUTOTHROTTLE_TARGET_CONCURRENCY = 4.0 DOWNLOAD_TIMEOUT = 45 RETRY_ENABLED = True RETRY_TIMES = 2 RETRY_HTTP_CODES = [403, 429, 500, 502, 503, 504, 522, 524] COMPRESSION_ENABLED = True ``` A retried request goes through the middleware again: without a session key it leaves from a new exit, which is exactly what you want after a 403 or 429. With a session key it stays on the same exit, which is what a multi-step flow needs. #### Keeping the bill down - Scrapy does not load images or scripts; HTML and JSON only, so a page costs its HTML size. - Enable compression (default) and avoid `Splash` or browser rendering unless the data needs it. - Cache with `HTTPCACHE_ENABLED = True` during development so you do not pay to re-fetch the same pages while debugging selectors. #### Per-domain politeness A pool is a way to be many polite visitors, not one impolite one. `CONCURRENT_REQUESTS_PER_DOMAIN` and AutoThrottle keep each target at a human-plausible rate per exit; the [acceptable use policy](https://proxshift.com/legal/acceptable-use) forbids anything that looks like an attack. ### Configuring a proxy in Chrome, Firefox and at the operating-system level (https://proxshift.com/guides/browser-and-system-proxy) For manual checks, account work or QA, a real browser through a residential exit is the most honest view of a site. Here is how each browser and OS takes the proxy, and the two settings that stop leaks. #### Which credentials to use Browsers prompt for proxy credentials once per session and remember them. Use a sticky username so the whole browsing session stays on one household: `USER-cc-de-city-berlin-sid-desk1-ttl-24h`. Alternatively whitelist your public IP in the dashboard and no prompt appears at all. #### Chrome and Chromium - Chrome uses the operating system's proxy settings by default; change them there (below) and every Chromium browser follows. - For one dedicated profile, start Chrome with flags: `--proxy-server=\"http://res.proxshift.com:9000\" --user-data-dir=/tmp/proxprofile`. The first navigation asks for the username and password. - SOCKS5 with remote DNS: `--proxy-server=\"socks5://res.proxshift.com:9001\" --host-resolver-rules=\"MAP * ~NOTFOUND , EXCLUDE res.proxshift.com\"` keeps DNS from leaking (whitelisted IP required: Chrome cannot send SOCKS5 credentials). - Extensions such as SwitchyOmega switch profiles per site and store credentials, useful when you alternate between direct and proxied browsing. #### Firefox 1. Settings → Network Settings → Manual proxy configuration. 2. HTTP Proxy `res.proxshift.com`, port `9000`, tick "Also use this proxy for HTTPS". Or SOCKS Host `res.proxshift.com`, port `9001`, SOCKS v5, and tick **Proxy DNS when using SOCKS v5**. 3. In `about:config`, set `media.peerconnection.enabled` to `false` to stop WebRTC from revealing your real address. 4. Firefox asks for the proxy credentials on the first request and can remember them per profile. #### macOS System Settings → Network → your interface → Details → Proxies: enable Web Proxy (HTTP) and Secure Web Proxy (HTTPS) with `res.proxshift.com` and port `9000`, tick "Proxy server requires password" and enter the sticky username and password. Safari and most apps follow the system setting; some command-line tools do not, use the environment variables instead. #### Windows Settings → Network & Internet → Proxy → Manual proxy setup: address `res.proxshift.com`, port `9000`. Windows has no field for credentials; Edge and Chrome will prompt on first use, or whitelist your IP. Add `localhost;127.*` to the exceptions. #### A PAC file for selective proxying ```javascript function FindProxyForURL(url, host) { // Only these sites go through the German exit; everything else is direct if (dnsDomainIs(host, ".example.de") || shExpMatch(host, "*.shop-example.de")) { return "PROXY res.proxshift.com:9000"; } return "DIRECT"; } ``` Point the browser or OS at the PAC URL (a local file works in Firefox; Chrome and Windows prefer an `http://` URL). Credentials are still prompted or whitelisted. #### Verify before you trust it - Open an IP-echo page: the address must be the exit, in the country you asked. - Open a WebRTC leak test: only the exit should appear. - Check the browser's language and time zone match the exit if the site cares about consistency. ### Proxies in anti-detect browsers: one profile, one country, one sticky session (https://proxshift.com/guides/anti-detect-browsers-proxy) Anti-detect browsers isolate fingerprints per profile; the proxy is what isolates the network identity. The rule that makes both work together: one profile, one sticky session, one consistent country. #### What the browser needs from you Every anti-detect browser has a proxy form per profile with the same fields: type (HTTP or SOCKS5), host, port, username, password. Fill them with the ProxShift gateway and a sticky username, or with a dedicated ISP address for accounts that must never change IP. | Field | Residential sticky session | Dedicated ISP address | | --- | --- | --- | | Type | HTTP (or SOCKS5) | HTTP (or SOCKS5) | | Host | res.proxshift.com | the IP from your list | | Port | 9000 (SOCKS5: 9001) | 8000 (SOCKS5: 8001) | | Username | USER-cc-us-state-ny-sid-profile17-ttl-24h | from your list | | Password | PASS | from your list | #### One profile, one session id Give each profile its own `-sid-` value and never reuse it elsewhere. The profile then lands on the same household for the whole lifetime (up to 24 hours on ProxShift), and a new day brings a new exit in the same city, which is how a real user on a consumer ISP behaves. If the profile must keep the exact same address for weeks, it needs an [ISP proxy](https://proxshift.com/isp-proxies), not a session. #### Align the profile with the exit - Time zone and language of the profile = country and city of the exit. - Geolocation permission, if enabled, near the exit's city. - Keep WebRTC in the "replace with proxy IP" or "disabled" mode the browser offers. - Test the profile's IP inside the browser before touching the account. #### Which network for accounts | Situation | Network | Why | | --- | --- | --- | | Many low-value accounts, daily activity | Residential sticky sessions | Cheap per account, natural daily IP change | | Valuable accounts that must not change IP | ISP proxy, one per profile | Static, residential-registered, unlimited traffic | | Platforms that challenge residential-grade IPs | Dedicated mobile device | Carrier IP, rotation on your command | | Bulk checks without logins | Residential rotating | Breadth over consistency | #### Import lists at scale Most anti-detect browsers import proxies as `host:port:user:pass` lines. Generate one line per profile with a distinct session id, or download your ISP list from the dashboard or `GET /v1/proxies?format=txt`, then map one line to one profile. ```text res.proxshift.com:9000:USER-cc-us-sid-p001-ttl-24h:PASS res.proxshift.com:9000:USER-cc-us-sid-p002-ttl-24h:PASS res.proxshift.com:9000:USER-cc-gb-sid-p003-ttl-24h:PASS ``` ### Giving an AI agent a proxy: environment variables, Playwright MCP and browser agents (https://proxshift.com/guides/ai-agents-proxy) Agents browse like impatient humans: many pages, unpredictable targets, no memory of which site blocked them. A residential exit per task, a session that lasts the task, and a spending ceiling turn that into a stable setup. #### The three problems agents create - **Unpredictable targets.** The agent decides where to go; you cannot pre-select datacenter for one site and residential for another. A residential exit is the safe default. - **Many hops per task.** Search, open, click, read, repeat: a task is a session, and should stay on one exit while it lasts. - **Unbounded spending.** An agent in a loop can fetch gigabytes. Give it a ceiling it cannot exceed. #### Environment variables for the whole toolchain Most Python HTTP stacks (requests, httpx, aiohttp, urllib) and many tools honour `HTTPS_PROXY`, `HTTP_PROXY` and `NO_PROXY`. Setting them in the agent's process proxies every tool that fetches pages, without touching their code. ```bash export HTTPS_PROXY="http://AGENTUSER-cc-us-sid-task-4f2a-ttl-2h:PASS@res.proxshift.com:9000" export HTTP_PROXY="$HTTPS_PROXY" export NO_PROXY="localhost,127.0.0.1,api.openai.com,api.anthropic.com" python agent.py ``` Exclude the model provider's API hosts with `NO_PROXY`: the LLM calls do not need a residential exit and would only cost traffic. #### Node.js agents Node's fetch (undici) ignores the environment by default. Install a global dispatcher once at startup and every fetch in the agent, including third-party tools, follows it. ```javascript import { EnvHttpProxyAgent, setGlobalDispatcher } from "undici"; setGlobalDispatcher(new EnvHttpProxyAgent()); // reads HTTPS_PROXY / NO_PROXY ``` #### Playwright MCP server The Playwright MCP server, used by Claude, ChatGPT-style tools and IDE agents to drive a browser, accepts a proxy at launch. Pass the gateway with a sticky username and the bypass list for local hosts. ```json { "mcpServers": { "playwright": { "command": "npx", "args": [ "@playwright/mcp@latest", "--proxy-server=http://res.proxshift.com:9000", "--proxy-bypass=localhost,127.0.0.1" ] } } } ``` Chromium prompts for proxy credentials, which an MCP session cannot answer; whitelist the machine's public IP in the dashboard so no prompt appears, and use a sub-user if you want that machine on its own traffic ceiling. Where the server exposes username and password options, pass a sticky username instead. #### Browser agents built on Playwright Frameworks such as browser-use expose Playwright's proxy settings (server, username, password) in their browser configuration. Give each agent run a fresh session id so parallel runs do not share an exit, and set the context locale and time zone to the exit's country. ```python proxy = { "server": "http://res.proxshift.com:9000", "username": f"AGENTUSER-cc-us-sid-{run_id}-ttl-1h", "password": "PASS", } # pass `proxy` where the framework accepts Playwright proxy settings ``` #### Ceilings: sub-users Create a [sub-user](https://proxshift.com/docs/authentication) per agent or per project with a traffic limit in GB. The agent gets its own username and password, its usage is reported separately, and it cannot spend beyond the ceiling whatever loop it falls into. #### Behavioural hygiene - Cap the agent's requests per domain and per minute; rotation does not excuse hammering. - Block images, media and fonts in the browser context; agents read text. - Log the session id with each task so a blocked run can be traced to its exit and replayed on a new one. ### Rotating vs sticky sessions: how to choose, per request (https://proxshift.com/guides/rotating-vs-sticky-sessions) Rotation is the default on a residential gateway; a sticky session is the exception you ask for. Choosing right per request is the difference between a smooth pipeline and one that logs itself out. #### The rule in one sentence Rotate when each request is independent; stick when the target ties requests together (a login, a cart, a paginated search, a multi-step form) or when it watches consistency. #### Decision table | Job | Mode | Username | | --- | --- | --- | | Collect product pages by URL | Rotating | USER-cc-de | | Search, then open three result pages | Sticky, 5 min | USER-cc-de-sid-q17-ttl-5m | | Add to cart, checkout, confirmation | Sticky, 30 min | USER-cc-us-sid-order42-ttl-30m | | Log in and act as one user for a day | Sticky, 24 h | USER-cc-gb-sid-acct9-ttl-24h | | Keep one address for weeks | Not a session: ISP proxy | ip:8000 from your list | | SERP sampling from many cities | Rotating, city per request | USER-cc-us-city-chicago | #### How the gateway decides - No `-sid-`: every new TCP connection gets a new exit. - `-sid-X`: all connections carrying X share one exit until `-ttl-` elapses (default 10 minutes, up to 24 hours). - Change X and you get a new exit at once; reuse X after the TTL and you get a new one too. - If the household behind X goes offline, the session moves to another exit in the same location; retry the failed request once. #### The keep-alive trap HTTP clients reuse connections. Without a session id you might still see the same IP for several requests because they rode the same connection; that is not stickiness, it is reuse, and it ends whenever the pool recycles the connection. If you need one exit, say so with `-sid-`; if you need a new exit per request, close the connection or use a fresh session id per request. #### Retries On a rotating job, a retry after 403 or 429 is a new visitor: cheap and effective. On a sticky job, retrying across exits breaks the flow and looks exactly like the automation the site is watching for; retry on the same session, back off, and only start a new session if the exit itself died. #### Parallelism Sticky sessions are independent of each other. Run a hundred with a hundred ids and you have a hundred consistent visitors; each holds its own exit for its own lifetime. Concurrency is unlimited on ProxShift, so the constraint is the pool size in your target city, not the gateway. ### How to test a proxy: exit IP, location, leaks, headers, speed and success rate (https://proxshift.com/guides/test-a-proxy) A proxy that "works" can still leak, sit in the wrong city or fail on your target. Ten minutes of checks, mostly with cURL, tell you what a sales page cannot. #### 1. The exit and its country ```bash curl -s -x http://USER-cc-de-city-berlin:PASS@res.proxshift.com:9000 https://api.ipify.org # then look the address up in one or two public geolocation databases ``` Country must match. At city level, accept the neighbouring town: databases disagree there. Run it a few times without `-sid-` to confirm rotation, then with a fixed `-sid-` to confirm stickiness. #### 2. Anonymity headers Fetch a header-echo endpoint over plain HTTP and read every header. Nothing should mention a proxy or an address other than the exit: no `X-Forwarded-For`, `Via`, `Forwarded`, `X-Real-IP`. Check over HTTP, not HTTPS, since a proxy cannot add headers inside TLS. #### 3. DNS With SOCKS5, compare `socks5://` and `socks5h://`: only the second resolves at the exit. With HTTP proxies the hostname always goes to the proxy. If a site behaves differently through the proxy than expected, a local DNS answer pointing at the wrong regional edge is a common cause. #### 4. WebRTC (browsers only) Open a WebRTC leak test in the browser you will use. Only the exit may appear; if your real address shows, disable WebRTC or set its IP policy to proxied-only. #### 5. Latency and throughput ```bash curl -s -o /dev/null -w 'connect %{time_connect}s ttfb %{time_starttransfer}s total %{time_total}s\n' \ -x http://USER-cc-de:PASS@res.proxshift.com:9000 https://example.com/ # a few hundred milliseconds of TTFB is normal on a household exit; seconds mean a slow line, try another session id ``` For throughput, download a 10 MB test file and read `%{speed_download}`; expect tens of Mbit/s on residential, hundreds on datacenter and ISP. #### 6. Success rate against your target ```bash ok=0; for i in $(seq 1 50); do code=$(curl -s -o /dev/null -w '%{http_code}' -m 30 -x "http://USER-cc-us:PASS@res.proxshift.com:9000" https://target.example/some/page) [ "$code" = 200 ] && ok=$((ok+1)) done; echo "$ok/50 succeeded" ``` Fifty requests cost a few megabytes. Check the *content* of a few responses too: a 200 with missing prices is a soft block, and only content inspection catches it. #### 7. What to conclude | Finding | Meaning | Action | | --- | --- | --- | | Wrong country | Parameter typo or unsupported code | Check -cc- (gb, not uk) | | Proxy headers present | Not an elite proxy | Change provider | | 403 or CAPTCHA on first request | Exit type too weak for the target | Residential → mobile, or datacenter → residential | | Blocks after N requests | Per-IP rate limit | Rotate more, slow down | | Slow everything | Household line | New session id, or ISP/datacenter for speed | ### Troubleshooting proxy errors: 407, 400, 402, 403, 429, 502 and timeouts (https://proxshift.com/guides/troubleshoot-proxy-errors) Half of proxy troubleshooting is knowing who answered: the gateway or the website. The status code and where it appears tell you, and each combination has one fix. #### Step 1: who answered? Run the failing request with `curl -v`. A status on the `CONNECT` line, before `Connection established`, comes from the gateway; a status after it comes from the destination. Browsers show gateway failures as `ERR_TUNNEL_CONNECTION_FAILED` or `ERR_PROXY_CONNECTION_FAILED`. #### Step 2: gateway codes | Code | ProxShift meaning | Fix | | --- | --- | --- | | 407 invalid_credentials | Username or password rejected | Copy the pair again; check for trailing spaces; whitelisted IP changed? | | 400 invalid_parameter | A username parameter is unknown or malformed | Check keys and values: -cc-gb not -cc-uk, -city- without spaces, -ttl- from 1m to 24h | | 402 insufficient_balance | No traffic or balance left | Top up; check the sub-user ceiling if you use one | | 403 blocked_destination | Port or destination not allowed | Port 25, UDP and IPv6-only targets are refused by design | | 502 no_exit_available | No exit matches the location right now | Widen: drop -city- or -asn-, keep -cc-; retry in a minute | | 502 exit_failed | The exit failed before the target | Retry once; the next connection picks another exit | | 504 target_timeout | The destination did not answer in time | Retry; check the target from another network | #### Step 3: destination codes | Code | Likely cause | Fix | | --- | --- | --- | | 403 (site page) | Exit type or fingerprint rejected | Residential or mobile exit; realistic client headers; sticky session for flows | | 429 | Per-IP rate limit | Rotate per connection; lower per-exit rate; honour Retry-After | | 200 with empty data | Soft block | Treat like 403; inspect content, not status | | 302 to a challenge page | Bot check | Slow down; real browser for that target; better exit type | | 5xx | Target trouble | Back off; not a proxy problem | #### Connection-level failures - `ECONNRESET`, `Connection reset by peer` mid-transfer: the household exit dropped. Retry once; on a sticky session the gateway rebinds to a new exit in the same location. - Idle timeouts: the gateway closes connections idle for 60 seconds. Long-polling needs a fresh connection. - TLS errors through the proxy: never normal. Check for a local interceptor (corporate proxy, antivirus) between you and the gateway. #### Step 4: decide 1. Credentials or parameters wrong → fix and retry (no cost). 2. Gateway found no exit → widen the location. 3. Target blocks the exit type → move the target to a stronger network: datacenter → residential → mobile. 4. Target rate-limits → rotate more and slow down; never both hammer and rotate. 5. Target broken → wait. ### How to estimate a proxy budget: pages × size × rate, with worked examples (https://proxshift.com/guides/estimate-a-proxy-budget) A proxy bill is arithmetic: how many requests, how heavy each one, which network. Three numbers and a ladder give you a figure you can defend before the first gigabyte is bought. #### Per-GB networks: the formula **monthly GB = requests per month × average bytes per request (both directions) ÷ 1,000,000,000**, then read the rate for a purchase of that size on the ladder. The tier applies to the whole purchase, so buying the month at once costs less than buying it in pieces. | Request type | Typical size | Notes | | --- | --- | --- | | HTML product or listing page | 200–500 KB | Compression on; no assets loaded | | JSON API response | 20–200 KB | The cheapest way to collect | | Search results page | 200–800 KB | Heavier with scripts inline | | Headless browser, assets blocked | 0.5–1.5 MB | HTML plus XHR calls | | Headless browser, everything loaded | 2–6 MB | Images and fonts dominate: block them | #### Worked examples on the residential ladder | Workload | GB per month | Rate | Monthly cost | | --- | --- | --- | --- | | 100,000 product pages at 350 KB | 35 | $1.82/GB | $63.70 | | 500,000 pages at 350 KB | 175 | $1.54/GB | $269.50 | | 2,000,000 API calls at 60 KB | 120 | $1.54/GB | $184.80 | | 50,000 rendered pages, assets blocked, 1 MB | 50 | $1.75/GB | $87.50 | | 50,000 rendered pages, everything loaded, 4 MB | 200 | $1.54/GB | $308 | Rates are the current ProxShift residential tiers; the [pricing page](https://proxshift.com/pricing) has the full ladder and a calculator that uses the same table. Mobile traffic follows its own ladder, from $2.62 per GB. #### Per-IP networks: the other arithmetic ISP and datacenter addresses are priced per IP and per term, so the question becomes: how many parallel identities or how many fixed exits do you need? One address per account, per whitelisted egress or per parallel task; multiply by the monthly rate of your term and zone; apply the volume discount from 10 addresses. Traffic is unlimited on ISP and pooled on datacenter (100 GB per address), so heavy pages cost nothing extra there. #### Choosing by cost per successful request The cheapest network is the one whose requests succeed. A datacenter address at a fraction of a cent per request is expensive if the target blocks it; a residential gigabyte that returns real pages is cheap. Estimate success rates per network on a small sample (fifty requests), then divide cost by successes. #### Five habits that halve the bill - Block images, media, fonts and trackers in browsers. - Prefer JSON endpoints and mobile pages to full desktop HTML. - Cache what does not change; re-fetch prices, not descriptions. - Send datacenter-tolerant targets to datacenter addresses. - Buy the month at once to reach a lower tier; traffic never expires on ProxShift, so there is no risk in buying ahead. ### How to choose a proxy provider: a 12-point checklist (https://proxshift.com/guides/choose-a-proxy-provider) Every provider sells "millions of IPs" and "99 % success". The differences that matter are in the rules: how addresses are sourced, how traffic is counted, what expires, what is published and what happens when something breaks. #### The checklist 1. **Sourcing.** For residential pools: do device owners opt in, get paid and can leave? A provider that cannot answer is a risk to you and to them. 2. **Coverage that matters to you.** Not the global pool figure: the pool in your target countries and cities, visible before or right after sign-up. 3. **Targeting levels.** Country everywhere; state, city and ASN where you need them; carrier on mobile. Check that they are set per request, not per plan. 4. **Session control.** Rotation per connection, sticky sessions with a lifetime you choose, up to how long, and what happens when an exit drops. 5. **Protocols and authentication.** HTTP(S) and SOCKS5 on the same account; username-password and IP whitelist; sub-users with ceilings if several people or agents share the account. 6. **Metering.** Both directions or one? Headers counted? Failed connections billed? Written down, not promised. 7. **Expiry.** Does unused traffic expire, and when? Non-expiring traffic changes the economics of buying larger tiers. 8. **Pricing transparency.** Every tier, term, zone and discount public; the checkout uses the same grid; no surcharge appears at payment. 9. **Payment and identity.** Which methods, which minimum, whether identity documents are required and at what threshold. 10. **Documentation.** Endpoints, parameters, error codes and limits precise enough to build against before you pay. 11. **Status and support.** A status page fed by real probes; a support channel that issues a reference and reaches a person. 12. **Rules.** An acceptable use policy that is published and enforced: it protects the pool you are about to depend on. #### Claims to read carefully | Claim | What it usually means | Ask instead | | --- | --- | --- | | "X million IPs" | Unique addresses seen over a month | How many are online now in my country? | | "99 % success rate" | Against an easy target, from the provider's own bench | What was the target, the rate and the client? | | "Unlimited bandwidth" | Often with a fair-use clause or throttling | What is the throttling threshold? | | "Free trial" | A few megabytes or a card on file | What does a real test cost, and does the balance persist? | #### Test in an hour 1. Fund the minimum and run the [test protocol](https://proxshift.com/guides/test-a-proxy): exit, headers, DNS, latency. 2. Send fifty requests to your real target from the network you intend to use; count successes and inspect content. 3. Try a sticky flow (search → three pages) and a rotating burst; watch the IPs. 4. Read the metering and expiry rules, then compare the effective price per successful request across candidates. #### How ProxShift answers the twelve points Consent-sourced residential capacity; pool sizes published per network, dated and defined (70M+ residential, 550K+ ISP, 550K+ datacenter and 4.9M+ mobile IPs, as of September 2026: monthly distinct addresses for the rotating pools, inventory for the static ones), with coverage listed country by country; country, US-state, city and ASN targeting from the username; sticky sessions up to 24 hours; HTTP(S) and SOCKS5 with password or whitelist and sub-user ceilings; both directions metered, failed connections free; traffic that never expires; every price public and identical at checkout; cryptocurrency from $20 with no identity documents; documentation that is the product contract; a status page probed every five minutes; an enforced acceptable use policy. Each claim links to the page where you can check it. ### Buying proxies with cryptocurrency: a step-by-step guide (https://proxshift.com/guides/buy-proxies-with-crypto) Paying in crypto removes cards, chargebacks and identity forms from the purchase. The mechanics are simple once you know three things: which network, how much, and how long to wait. #### Before you start - A wallet or exchange account holding the coin you will use. For small amounts, a low-fee coin (Litecoin, Tron, Solana, or a stablecoin on a low-fee network) keeps fees at cents. - The USD amount you want on the balance: at ProxShift the minimum is $20, and larger top-ups carry a bonus (+10% from $100, +25% from $250, +40% from $500, +50% from $1,000). - Five to thirty minutes, depending on the coin's confirmation time. #### Step by step 1. In the wallet section of your account, choose the amount in USD and the coin. The checkout shows an address, the exact coin amount and, for networks that need one, a memo or tag. 2. Check the **network**: a USDT address on Tron cannot receive USDT sent on Ethereum. The checkout names the network; your wallet must send on the same one. 3. Send exactly the amount shown. If your exchange deducts a withdrawal fee from the amount, add it on top so the full amount arrives. 4. Wait for confirmations. The balance is credited when the transaction reaches the depth the checkout indicates; seconds on Solana or Tron, minutes on Litecoin or Ethereum, longer on Bitcoin when the network is busy. 5. Spend it: buy gigabytes or rent addresses from the balance. Every top-up appears in the ledger with its transaction hash. #### Amounts, rates and mistakes | Situation | What happens | | --- | --- | | Sent slightly less | Credited at the value received | | Sent more | Credited in full | | Rate moved while confirming | The USD value is fixed at the rate when the transaction is detected | | Wrong network | Usually unrecoverable; always match the network shown at checkout | | Forgot the memo | Contact support with the hash; recovery depends on the network | #### Choosing a coin | Priority | Coin | Why | | --- | --- | --- | | Lowest fee, fastest | Tron, Solana, Litecoin | Cents or less, seconds to minutes | | Fixed dollar value | USDT, USDC | No rate movement between sending and crediting | | Privacy | Monero | Amounts and parties shielded on-chain | | Already held | Bitcoin, Ethereum | Universal; mind the fee at busy times | #### Privacy and records At ProxShift an email address opens the account and the coin funds it; no identity documents, no phone number. What is stored is what billing and abuse handling require, for the periods the [privacy policy](https://proxshift.com/legal/privacy) lists. Your own wallet's history is yours to manage: a fresh receiving address per purchase on your side, and Monero if the chain itself must not show the payment. #### Refunds Unused balance can be refunded to the wallet it came from, minus network fees; consumed traffic and delivered terms cannot. Bonus credit is spent like balance and never paid out. Details in the [refund policy](https://proxshift.com/legal/refunds). ## Glossary ### Proxy server (https://proxshift.com/glossary/proxy-server) A proxy server is an intermediary machine that receives a client's request, forwards it to the destination under the proxy's own IP address, and relays the response back. The destination sees the proxy, not the client, which is what makes proxies useful for changing apparent location, distributing traffic across many addresses and keeping a stable exit for a session. ### Forward proxy (https://proxshift.com/glossary/forward-proxy) A forward proxy is a proxy server placed in front of clients: applications send it their requests and it forwards them to any destination on the internet, replacing the client's IP address with its own. Every commercial proxy network, residential, ISP, datacenter or mobile, is a forward proxy. ### Reverse proxy (https://proxshift.com/glossary/reverse-proxy) A reverse proxy is a server that sits in front of one or more origin servers and accepts requests from the public on their behalf, then forwards them internally. Load balancers, CDNs and API gateways are reverse proxies. It is the opposite of the forward proxies that proxy providers sell, and it is also the layer that scores incoming visitors on protected websites. ### Residential proxy (https://proxshift.com/glossary/residential-proxy) A residential proxy routes traffic through an IP address that an internet service provider assigned to a real household device. Because the address belongs to a consumer ISP and behaves like one, websites treat the request as an ordinary visitor from that home and city. Residential proxies are usually sold as a rotating pool billed per gigabyte, with country, state, city and ASN targeting and sticky sessions of limited duration. ### ISP proxy (https://proxshift.com/glossary/isp-proxy) An ISP proxy, also called a static residential proxy, is an IP address registered to a consumer internet service provider but hosted on datacenter hardware and assigned to a single customer for a term. Websites classify it as a home connection, while the customer gets the speed and uptime of a wired uplink and an address that never changes during the rental. ISP proxies are sold per IP, usually with unlimited traffic. ### Datacenter proxy (https://proxshift.com/glossary/datacenter-proxy) A datacenter proxy uses an IP address hosted in a commercial facility and registered to a hosting company rather than to a consumer ISP. It is the fastest and cheapest proxy type, with wired uplinks and predictable latency, and the easiest for websites to recognise as non-residential. Datacenter proxies are sold as dedicated (one customer) or shared addresses, per IP and per term. ### Mobile proxy (https://proxshift.com/glossary/mobile-proxy) A mobile proxy routes traffic through an IP address that a cellular carrier assigned to a real 4G or 5G device. Carriers place thousands of subscribers behind each address with carrier-grade NAT, so blocking a mobile IP means blocking real customers; websites therefore treat mobile addresses with more tolerance than any other kind. Mobile proxies are sold as a rotating pool billed per gigabyte or as a dedicated device rented per term. ### Rotating proxy (https://proxshift.com/glossary/rotating-proxy) A rotating proxy is a gateway that assigns a different exit IP address to each new connection, or changes it after a set interval, drawing from a pool of addresses. The client keeps one hostname and one credential pair; the rotation happens on the provider's side. It is the standard delivery mode for residential and mobile pools and the natural answer to per-IP rate limits. ### Static proxy (https://proxshift.com/glossary/static-proxy) A static proxy is a proxy address that stays the same for the whole rental period, as opposed to a rotating gateway that changes exits behind one hostname. ISP proxies, dedicated datacenter proxies and dedicated mobile devices are static; residential and mobile pools are rotating. Static addresses suit logins, whitelists and anything that must present one consistent identity over time. ### Dedicated proxy (https://proxshift.com/glossary/dedicated-proxy) A dedicated proxy is an IP address assigned to a single customer for the whole term: nobody else sends traffic through it, so its reputation, rate limits and blocks depend only on that customer's own behaviour. The opposite is a shared proxy, used by several customers at once. Dedicated is the norm for ISP proxies, quality datacenter proxies and mobile devices. ### Shared proxy (https://proxshift.com/glossary/shared-proxy) A shared proxy is an IP address used simultaneously by several customers of the same provider. It costs less than a dedicated address because the provider sells the same resource several times, but its reputation and rate limits are shaped by everyone using it. Rotating residential and mobile pools are shared by design; static shared datacenter proxies are the budget end of the market. ### Backconnect proxy (https://proxshift.com/glossary/backconnect-proxy) A backconnect proxy is a gateway server that you connect to at one fixed hostname and port, and which forwards each connection through a different exit IP from a pool behind it. The term describes the architecture of rotating residential and mobile services: you never configure the exits themselves, only the gateway, and the gateway "connects back" to a device for each request. ### Proxy gateway (https://proxshift.com/glossary/proxy-gateway) A proxy gateway is the entry point of a proxy network: the hostname and port that clients connect to, which authenticates them, reads their targeting parameters and forwards each connection to a suitable exit address. One gateway can front millions of exits, which is why residential and mobile services are configured once and steered from the username rather than by switching hosts. ### Exit IP (https://proxshift.com/glossary/exit-ip) The exit IP is the public IP address from which a proxied request finally reaches its destination: a household device for a residential proxy, a hosted address for an ISP or datacenter proxy, a carrier address for a mobile proxy. Everything the destination decides about location, provider and reputation is decided about the exit, not about the gateway you connected to. ### Proxy pool (https://proxshift.com/glossary/proxy-pool) A proxy pool is the collection of exit IP addresses available to a gateway at a given moment. Its size, geographic spread and turnover determine how many distinct addresses you can get in a country or city, how often the same address is reused against a target, and how quickly blocked exits are replaced. Advertised pool sizes usually count addresses seen over a month; the number online right now is smaller. ### Proxy anonymity levels (https://proxshift.com/glossary/anonymity-levels) Proxy anonymity levels describe what a proxy tells the destination about the client. A transparent proxy forwards the client's real IP in headers such as X-Forwarded-For; an anonymous proxy hides the real IP but announces itself through headers such as Via; an elite (high-anonymity) proxy adds no proxy headers at all, so the request looks like it came directly from the exit address. Commercial proxies meant for privacy or data collection are elite by design. ### HTTP proxy (https://proxshift.com/glossary/http-proxy) An HTTP proxy is a proxy server addressed with the HTTP protocol: the client sends it either a full-URL request for plain HTTP, or a CONNECT request that opens a tunnel for HTTPS and other TCP traffic. Almost every HTTP client, browser and scraping framework supports it natively, which makes it the default choice for web work; SOCKS5 is the alternative for non-HTTP protocols. ### SOCKS5 proxy (https://proxshift.com/glossary/socks5-proxy) A SOCKS5 proxy relays TCP connections at the transport level without understanding the application protocol, so it can carry HTTP, HTTPS, SMTP, custom binary protocols or anything else over TCP. SOCKS5 adds username-password authentication and, optionally, remote DNS resolution and UDP association. It is the protocol to use for tools that are not HTTP clients or that need the proxy to resolve hostnames. ### IP rotation (https://proxshift.com/glossary/ip-rotation) IP rotation is the practice of sending successive requests from different exit IP addresses, either automatically at the proxy gateway or by cycling through a list of static proxies in the client. It spreads a workload across many addresses so that per-IP rate limits, blocks and reputation damage never concentrate on one, and it is the default behaviour of residential and mobile proxy pools. ### Sticky session (https://proxshift.com/glossary/sticky-session) A sticky session binds a series of requests to one exit IP address for a defined duration, instead of rotating on every connection. The client attaches a session identifier to its proxy username; every connection carrying the same identifier is routed through the same exit until the session lifetime ends or the exit goes offline. Sticky sessions make logins, shopping carts and multi-page flows work through a rotating pool. ### Session ID (https://proxshift.com/glossary/session-id) A proxy session ID is an arbitrary identifier that the client adds to its proxy username so that the gateway groups requests into a session and routes all of them through the same exit IP. Any value works; the gateway only compares identifiers. Using a new identifier is the simplest way to force a new exit, and using one identifier per account, basket or task is how parallel sessions are isolated from each other. ### Session TTL (https://proxshift.com/glossary/session-ttl) A session TTL (time to live) is the lifetime of a sticky proxy session: the period during which requests carrying the same session identifier are routed through the same exit IP. When it elapses, the next request with that identifier gets a new exit. Lifetimes range from a minute to a day depending on the provider; longer lifetimes trade freshness for continuity. ### Keep-alive and rotation (https://proxshift.com/glossary/keep-alive) HTTP keep-alive lets a client send several requests over one TCP connection. Through a rotating proxy, the exit is chosen when the connection is opened, so every request reused on that connection leaves from the same IP. Clients that pool connections therefore see fewer IP changes than they expect; forcing a new connection per request restores per-request rotation. ### Concurrent connections (https://proxshift.com/glossary/concurrent-connections) Concurrent connections, often called threads in proxy marketing, are the number of simultaneous connections a customer may keep open through a proxy service. Some providers cap them per plan; others, ProxShift included, leave them unlimited and bill only traffic or addresses. The practical limit is then the target's tolerance and the size of the pool in the location you use. ### Geo-targeting (https://proxshift.com/glossary/geo-targeting) Proxy geo-targeting is the ability to choose where the exit IP address is located, so that the destination sees a visitor from a specific country, state, city or provider. On residential and mobile pools it is expressed per request through parameters in the proxy username; on static products it is chosen when the addresses are ordered. It is what lets one account see localized prices, search results and content from any market. ### Country targeting (https://proxshift.com/glossary/country-targeting) Country targeting restricts the exit IP to a chosen country, identified by its ISO 3166-1 alpha-2 code (us, de, br…). It is the most common and most reliable targeting level: geolocation databases agree on countries far more than on cities, and every proxy network offers it. On pool gateways the code travels in the username; on dedicated products it is chosen at the order. ### State targeting (https://proxshift.com/glossary/state-targeting) State targeting restricts the exit IP to a specific US state, identified by its two-letter postal code (tx, ca, ny…). It exists because so much American commerce, advertising and regulation varies by state: sales tax, shipping, insurance quotes, gambling and lottery rules, local ads. Outside the United States, region-level targeting is uncommon and city targeting fills the gap. ### City targeting (https://proxshift.com/glossary/city-targeting) City targeting restricts the exit IP to addresses that geolocation databases place in a given city. It is used for local search results, delivery pricing, real-estate listings, ad verification and anything else served by metro area. Its limits are the pool size in that city, the precision of geolocation for smaller places, and the fact that a household's "city" is whatever the database says, not a GPS position. ### ASN targeting (https://proxshift.com/glossary/asn-targeting) An autonomous system number (ASN) identifies a network operator on the internet: an ISP, a carrier, a hosting company. ASN targeting restricts the exit IP to addresses announced by one operator, for example Comcast (AS7922) or Deutsche Telekom (AS3320). It is used when a target treats providers differently, when an audience must be sampled by ISP, or when a mobile carrier must be chosen. ### Carrier targeting (https://proxshift.com/glossary/carrier-targeting) Carrier targeting selects the mobile network operator behind a mobile proxy exit: AT&T rather than T-Mobile, Vodafone rather than Orange. Platforms and apps sometimes behave differently per operator, and an account created on one carrier looks more consistent when it keeps appearing from it. On rotating mobile pools the carrier is chosen with the operator's AS number; on dedicated devices it is fixed when the device is provisioned. ### CGNAT (https://proxshift.com/glossary/cgnat) Carrier-grade NAT (CGNAT) is the network address translation that mobile and some fixed-line operators perform at scale, sharing one public IPv4 address between hundreds or thousands of subscribers. For websites it means that a single mobile IP represents many real people, so blocking it would block them all; that is the root of the high tolerance mobile proxy exits enjoy, and the reason mobile IPs rotate naturally as devices move between gateways. ### IP geolocation (https://proxshift.com/glossary/ip-geolocation) IP geolocation is the mapping of an IP address to a physical location, built by commercial database vendors from regional registry records, ISP allocations, latency measurements and user-contributed corrections. Websites use it to localize content and to check visitors; proxy providers use it to place exits. Country accuracy is very high, city accuracy varies with the size of the city and the type of network. ### Username parameters (https://proxshift.com/glossary/username-parameters) Username parameters are key-value pairs appended to the username of a proxy credential (for example USER-cc-de-city-berlin-sid-a1b2) that tell the gateway which exit to choose and how long to keep it. They let a single hostname and credential serve every country, city, provider and session mode without generating new proxy lists, because the choice travels with each connection. ### HTTP CONNECT (https://proxshift.com/glossary/https-connect) HTTP CONNECT is the request method a client sends to an HTTP proxy to ask for a TCP tunnel to a host and port, typically port 443. Once the proxy answers 200, the client speaks directly to the destination through that tunnel and negotiates TLS end to end, so the proxy sees only the destination name and encrypted bytes. It is how every HTTPS request travels through an HTTP proxy. ### Proxy authentication (https://proxshift.com/glossary/proxy-authentication) Proxy authentication is how a proxy gateway identifies the customer behind a connection before forwarding it. Two methods dominate: username and password, sent in the Proxy-Authorization header for HTTP proxies or in the SOCKS5 handshake, and IP whitelisting, where connections from registered source addresses are accepted without credentials. Most providers support both and let them coexist. ### IP whitelisting (https://proxshift.com/glossary/ip-whitelisting) IP whitelisting authenticates proxy connections by their source IP address: the customer registers the public addresses of its machines, and the gateway accepts connections from them without a username or password. It removes secrets from configuration and suits fixed servers, but it fails when the source address changes and it does not work from networks whose public IP is shared with strangers. ### Remote DNS resolution (https://proxshift.com/glossary/remote-dns) Remote DNS resolution means the proxy, not the client, translates the destination hostname into an IP address. With HTTP proxies this is automatic, since the client sends the hostname in the request or the CONNECT line; with SOCKS5 it depends on the client sending the name (socks5h) rather than a pre-resolved address (socks5). Resolving remotely keeps DNS queries in the exit's network and returns the answers a local user would get. ### TLS passthrough (https://proxshift.com/glossary/tls-passthrough) TLS passthrough is the behaviour of a proxy that relays an HTTPS connection without decrypting it: the client negotiates TLS with the destination through the tunnel, the destination's own certificate is presented, and the proxy sees only the server name and ciphertext. The opposite, TLS interception, requires the client to trust the proxy's certificate authority and lets the proxy read and modify content; commercial proxy networks do not do this. ### UDP and proxies (https://proxshift.com/glossary/udp-proxying) UDP proxying is the relay of connectionless datagrams through a proxy, which SOCKS5 defines with the UDP ASSOCIATE command but which most commercial proxy networks do not support. HTTP proxies are TCP by nature, and residential and mobile gateways relay TCP streams only. Applications that insist on UDP, including HTTP/3 over QUIC, DNS over UDP and most VoIP or gaming protocols, fall back to TCP or bypass the proxy. ### IPv4 and IPv6 proxies (https://proxshift.com/glossary/ipv4-vs-ipv6) IPv4 and IPv6 are the two versions of the Internet Protocol. IPv4 addresses are scarce, expensive and accepted everywhere, which is why serious proxy networks are built on them. IPv6 addresses are practically unlimited and cheap, so IPv6 proxies are sold in huge quantities at low prices, but a large share of websites do not accept IPv6 connections at all and those that do apply stricter scoring to /64 blocks. For general web work, IPv4 is the safe default. ### Proxy port (https://proxshift.com/glossary/proxy-port) A proxy port is the TCP port on which a proxy listens; providers usually run one port per protocol on the same hostname, for example 9000 for HTTP(S) and 9001 for SOCKS5, and sometimes dedicate port ranges to sticky sessions or countries. The port does not change the exit or the price; it only decides which protocol the client speaks to the gateway. ### IP reputation (https://proxshift.com/glossary/ip-reputation) IP reputation is the assessment a website or a security vendor makes of an IP address from what is known about it: who announces it (consumer ISP, carrier, hosting company), whether it appears on abuse blocklists, whether it has recently produced attacks, spam or bot traffic, and how many distinct users it seems to represent. Requests from a low-reputation address get challenges, degraded content or blocks; residential and mobile addresses start with a higher reputation than hosting ranges. ### Bot detection (https://proxshift.com/glossary/bot-detection) Bot detection is the set of techniques a website uses to tell automated clients from human visitors: IP reputation and autonomous-system class, request rate and timing, TLS and HTTP fingerprints, browser and device fingerprints, JavaScript challenges and behavioural signals. The verdict decides whether a request receives the normal page, a CAPTCHA, degraded content or a block. Proxies address the IP part of that equation and nothing else. ### Browser fingerprinting (https://proxshift.com/glossary/browser-fingerprinting) Browser fingerprinting identifies a client from the combination of attributes it exposes: user agent, screen size, fonts, canvas and WebGL rendering, time zone, language, installed features, and at the transport level the exact way its TLS and HTTP/2 stacks negotiate. The combination is often unique, so a website can recognise the same automation across many IP addresses. Proxies change the IP; they do not change the fingerprint. ### CAPTCHA (https://proxshift.com/glossary/captcha) A CAPTCHA is a challenge a website serves when it is not sure a visitor is human: an image puzzle, a checkbox backed by risk analysis, or an invisible JavaScript proof of work. Through a proxy, frequent CAPTCHAs point at a low-reputation exit (hosting ranges, overused pool addresses), at a request rate above the site's comfort, or at a client fingerprint that reads as automation. Changing the exit type, slowing down and keeping sessions consistent reduce them more than solving them does. ### Rate limiting (https://proxshift.com/glossary/rate-limiting) Rate limiting is a website's cap on how many requests an IP address, a session or an account may send in a period, enforced with HTTP 429 responses, delays or temporary blocks. Proxies help when the limit is per address: rotating across many exits turns a per-IP ceiling into a budget you control. They do not help when the limit is per account or per fingerprint, and they never excuse hammering a target. ### Geo-blocking (https://proxshift.com/glossary/geo-blocking) Geo-blocking is the practice of restricting or varying a website's content by the visitor's geographic location as inferred from the IP address: catalogues, prices, licences, availability, ads and search results all differ by country, and some services refuse foreign visitors outright. A proxy exit in the target country shows exactly what a local sees, which is the basis of price monitoring, ad verification, SERP tracking and localisation testing. ### WebRTC leak (https://proxshift.com/glossary/webrtc-leak) A WebRTC leak occurs when a browser configured to use a proxy for web traffic still discloses the device's real public or local IP addresses through WebRTC, the real-time communication API, because WebRTC gathers connection candidates directly rather than through the proxy. Any page can trigger it with JavaScript, so a browser session through a proxy is only as private as its WebRTC settings. ### DNS leak (https://proxshift.com/glossary/dns-leak) A DNS leak happens when a client resolves destination hostnames through its own resolver instead of through the proxy, so the local network or ISP learns which sites are visited even though the requests themselves travel through the exit. With HTTP proxies the hostname is sent to the proxy and no leak occurs; with SOCKS5 it depends on whether the client sends the name (socks5h) or resolves it first (socks5). ### IP blocklists (https://proxshift.com/glossary/blocklists) IP blocklists are databases of addresses reported for spam, attacks, malware or proxy use, published by anti-abuse organisations and security vendors and queried by websites, mail servers and fraud systems. An exit that appears on a relevant list is challenged or refused regardless of how it is used today. Providers of dedicated addresses screen inventory against these lists; on rotating pools the provider retires listed exits. ### Proxy header leakage (https://proxshift.com/glossary/header-leakage) Proxy header leakage is the disclosure of proxy use, or of the client's real address, through HTTP headers such as X-Forwarded-For, Via, Forwarded or X-Real-IP that some proxies add to forwarded requests. It only affects plain HTTP, since a proxy cannot alter the encrypted content of an HTTPS request, and it is the defining difference between transparent, anonymous and elite proxies. ### Consent-sourced residential IPs (https://proxshift.com/glossary/consent-sourced-ips) Consent-sourced residential IPs are household exits obtained from device owners who explicitly agreed to share bandwidth, usually through an SDK embedded in an application that discloses the arrangement and compensates them, and who can withdraw at any time. The alternative sources, botnets and undisclosed bundling, are illegal and unstable. Sourcing is the first ethical and practical question to ask a residential provider, because it determines both legality and pool stability. ### Acceptable use policy (https://proxshift.com/glossary/acceptable-use-policy) An acceptable use policy (AUP) is the contractual list of what a proxy network may and may not be used for: typically permitted public data collection, verification and testing, and forbidden attacks, fraud, spam, unauthorized access, harvesting of personal data without a legal basis and anything illegal where the customer or the target operates. Enforcement protects the people behind residential exits, the reputation of the pool and, ultimately, every other customer's success rate. ### Silent ban (https://proxshift.com/glossary/silent-ban) A silent ban, or soft block, is a website's response to suspected automation that looks like success: HTTP 200 with a page whose prices, listings or search results are missing, stale, randomised or replaced by a generic version. It is harder to detect than a 403 because the request "worked". Monitoring the content itself, not just the status code, is the only reliable way to catch it. ### Per-GB billing (https://proxshift.com/glossary/per-gb-billing) Per-GB billing charges for the volume of data that passes through the proxy, measured in gigabytes in both directions, rather than for the number of addresses or the length of a rental. It is the standard model for residential and mobile pools, where the scarce resource is household or cellular bandwidth. The price per gigabyte usually falls with the size of the purchase, and the traffic you buy is either valid for a period or, at some providers, forever. ### Traffic metering (https://proxshift.com/glossary/traffic-metering) Traffic metering is the accounting a provider applies to per-GB products: which bytes are counted (request and response, headers, TLS overhead), in which direction, at what granularity, and which are excluded (failed connections, gateway errors). Small differences in these rules change a bill noticeably at scale, so the metering policy belongs in the documentation, not in a support answer. ### Volume tiers (https://proxshift.com/glossary/volume-tiers) Volume tiers are price levels that decrease as the size of a purchase increases: a gigabyte bought in a 100 GB purchase costs less than one bought alone. The tier is usually determined by the amount of a single purchase and applies to all of it. Tiers are the main reason two customers pay very different rates for the same product, and the first thing to compare between providers at your actual volume. ### Volume discount (https://proxshift.com/glossary/volume-discount) A volume discount reduces the per-address price of an order of dedicated proxies once the quantity crosses a threshold, for example 5 % from 10 addresses and 25 % from 500. Unlike per-GB tiers it applies to addresses and terms, stacks with the lower monthly rate of longer terms, and is computed on the whole order rather than on the addresses above the threshold. ### Pay-as-you-go proxies (https://proxshift.com/glossary/pay-as-you-go) Pay-as-you-go proxies are bought in the quantity you need at the moment you need it, without a subscription, a monthly minimum or an allowance that resets. You fund an account and spend it on gigabytes or addresses; the alternative is a plan that bills every month whether or not the allowance was used. Pay-as-you-go suits irregular workloads, tests and anyone who dislikes paying for unused capacity; plans suit steady high volumes when they come with lower rates. ### Traffic expiry (https://proxshift.com/glossary/traffic-expiry) Traffic expiry is the rule that decides what happens to purchased but unused gigabytes: many providers void them after 30 to 90 days or at the end of a billing cycle, some roll them over, and a few keep them valid indefinitely. For irregular workloads the difference is the whole bill, because buying a large tier for a lower rate only pays off if the traffic can be used over time. ### Prepaid wallet (https://proxshift.com/glossary/prepaid-wallet) A prepaid wallet is an account balance, usually held in a fiat currency such as USD, that the customer funds in advance and from which every purchase of traffic or addresses is deducted. It replaces cards on file and recurring charges: nothing is billed that was not funded first, and the balance is the customer's spending limit. Wallets are the natural fit for pay-as-you-go pricing and for cryptocurrency top-ups, whose exchange rate is fixed when the balance is credited. ### Minimum top-up (https://proxshift.com/glossary/minimum-top-up) The minimum top-up is the smallest amount a provider accepts to fund an account or to buy a first product. It sets the cost of testing a network on a real workload, replaces the free trial at providers that do not offer one, and, for crypto payments, must be high enough to absorb network fees. Anything not used stays on the balance if the provider does not expire it. ### Term billing (https://proxshift.com/glossary/term-billing) Term billing charges a fixed price per dedicated address for a chosen rental period, typically 24 hours, 30, 60 or 90 days, with traffic either unlimited or pooled. Longer terms cost less per month, the address stays the same for the whole period, and renewing before the end keeps it. It is the model of ISP proxies, dedicated datacenter proxies and dedicated mobile devices. ### Location zone pricing (https://proxshift.com/glossary/location-zone-pricing) Location zone pricing groups countries into zones with a price multiplier for dedicated products, reflecting what ISP address blocks, colocation and carrier plans cost in each region; the reference zone is usually the United States. Per-gigabyte traffic on residential and mobile pools is normally priced the same in every country, because it is sold by volume rather than by address. ### Traffic pool (https://proxshift.com/glossary/traffic-pool) A traffic pool is a monthly allowance attached to each dedicated address and summed across all addresses of an order: ten addresses with 100 GB each share one 1,000 GB pool, drawn on by whichever address does the work. It is a middle path between unlimited traffic and strict per-address caps, common on datacenter proxies. When the pool is exhausted, the provider either throttles, bills overage or lets you add traffic. ### Cryptocurrency payment (https://proxshift.com/glossary/crypto-payment) Cryptocurrency payment funds a proxy account by sending a coin (Bitcoin, Ethereum, USDT, USDC, Litecoin, Monero, Solana, Tron, Dogecoin…) to an address generated for that top-up; once the transaction reaches the required number of confirmations, the balance is credited in USD at the rate of the moment. It requires no card, no bank and typically no identity documents, cannot be charged back, and its cost is the network fee the sender pays. Some providers accept it alongside cards; a few accept only crypto. ### KYC (identity verification) (https://proxshift.com/glossary/kyc) KYC, know your customer, is the collection of identity documents and business information before a service is sold. Proxy providers differ widely: some require it for every account, some only above a spending threshold or for specific products, and some never ask, relying on an enforced acceptable use policy and abuse handling instead. The choice reflects the provider's payment methods, jurisdiction and target customers, and it decides how much personal data a customer must hand over to buy bandwidth. ### Success rate (https://proxshift.com/glossary/success-rate) Proxy success rate is the percentage of requests sent through a proxy that return a usable response from the destination, as opposed to a connection failure, a gateway error, a block or a challenge. Published figures are measured against specific targets and are not comparable across providers unless the methodology is; for your own workload, the meaningful number is the rate against your target, at your rate, with your client. ### Latency and response time (https://proxshift.com/glossary/latency) Proxy latency is the additional time a request spends because it goes through the gateway and out of an exit before reaching the destination: the network distance to the gateway, the hop to the exit, and the exit's own connection quality. Datacenter and ISP exits on wired uplinks add tens of milliseconds; residential exits add a few hundred because of household lines; mobile exits vary with the cell. Latency matters for interactive flows and matters little for bulk collection. ### Throughput (https://proxshift.com/glossary/throughput) Throughput is the volume of data a proxied connection can move per second, bounded by the slowest link on the path: for residential exits the household's upload and download speed, for mobile exits the cell, for datacenter and ISP exits the facility uplink. Aggregate throughput grows with concurrency, so a pool can move large volumes even when each exit is modest; per-connection throughput is what matters for large files and media. ### Gateway error codes (https://proxshift.com/glossary/gateway-errors) Gateway error codes are HTTP status codes generated by the proxy gateway rather than by the destination website, signalling that a request could not be forwarded: missing or wrong credentials, an invalid targeting parameter, an empty balance, a blocked destination, or no exit available for the requested location. Telling them apart from destination errors is the first step of any troubleshooting, because the fix is on your side of the gateway. ### HTTP 407 Proxy Authentication Required (https://proxshift.com/glossary/http-407) HTTP 407 Proxy Authentication Required is the status a proxy returns when a request arrives without valid proxy credentials: no Proxy-Authorization header, a wrong username or password, or a source IP that is not whitelisted when whitelisting is the only method configured. It is the proxy's counterpart of 401 and means the request never left the gateway; fixing the credentials or the whitelist resolves it. ### Target timeout (https://proxshift.com/glossary/target-timeout) A target timeout occurs when the destination does not complete the connection or send a response within the time the gateway or the client allows, and the request fails with a 504 from the gateway or a timeout exception in the client. Through residential and mobile exits, slow household or cellular links raise the chance of timeouts on heavy pages; the remedies are realistic client timeouts, one retry, and lighter requests. ## Frequently asked questions ### General **Which payment methods do you accept?** Cryptocurrency only. You fund a prepaid wallet with Bitcoin, Ethereum, USDT, USDC, Litecoin, Monero, Solana, Tron, Dogecoin and other major coins, and every purchase is paid from that balance. Prices are shown in USD; the amount of crypto due is fixed at checkout. **Do I need to verify my identity?** No. An email address is all it takes to open an account. What we do enforce is the acceptable use policy: the network may not be used against the law or to harm the people whose connections make it possible. **Does unused traffic expire?** No. Residential and mobile traffic bought per GB stays on your balance until you use it, whether that takes a week or a year. Dedicated ISP, datacenter and mobile IPs run for the term you choose and can be renewed before they end. **What is the difference between the four proxy types?** Residential IPs belong to real home connections and are the hardest to detect, billed per GB. ISP proxies are residential-registered addresses hosted in datacenters: fast, static and dedicated to you. Datacenter proxies are the fastest and cheapest, best where trust requirements are low. Mobile proxies use 4G/5G carrier IPs shared by thousands of real phones, which makes them the most trusted of all. **How large is the IP pool?** 70M+ residential IPs across 195 countries, 4.9M+ mobile IPs on 4G/5G carriers, 550K+ ISP addresses and 550K+ datacenter addresses, as of September 2026. Like every published pool size, the residential and mobile figures count distinct addresses available over a month, not the number online at one instant; the ISP and datacenter figures are the inventory your order is drawn from. What decides a job is the pool in your target country, so test there first with a small purchase: unused traffic stays on your balance. **Can I target a specific city, state or ISP?** Yes. Residential proxies support country, state, city and ASN targeting through parameters in the proxy username, so you can change location without regenerating anything. Datacenter proxies offer state and city selection, ISP proxies offer country and city, and mobile proxies let you pick the country and carrier. **How do rotating and sticky sessions work?** In rotating mode every request leaves from a different IP. In sticky mode you attach a session ID to the username and keep the same IP for the duration you set, or until the IP goes offline, in which case a replacement in the same location is assigned. **Which protocols and authentication methods are supported?** HTTP, HTTPS and SOCKS5 on every product. Authenticate with a username and password, or whitelist your server IPs and connect without credentials. **Is there a free trial or a refund policy?** There is no free trial; the $20 minimum top-up exists so you can test with a small amount before committing to volume. If a product does not work as described, contact support from your account and we will replace it or credit your wallet. ### Residential **What is a residential proxy?** A residential proxy routes your request through an IP address that an internet provider assigned to a real household device. To the destination website your traffic looks like an ordinary visitor from that home and that city, which is why residential IPs pass checks that datacenter addresses fail. **How is it different from ISP, datacenter and mobile proxies?** Datacenter IPs live in hosting facilities: cheap and fast, but easy to flag. ISP proxies are residential-registered addresses hosted on datacenter hardware: static, fast and trusted, sold per IP. Mobile proxies use 4G/5G carrier addresses shared by many phones, the hardest of all to block. Residential proxies sit in the middle: real household IPs, rotating or sticky, billed per GB. **Can residential proxies be detected?** Far less often than datacenter IPs, because the address belongs to a consumer ISP and behaves like one. Detection still depends on how you use them: matching the location to your account, keeping sessions consistent and respecting request rates matters as much as the IP itself. **How many residential IPs are in the pool?** More than 70 million (70M+) across 195 countries, as of September 2026. As with every published pool size, the figure counts distinct household addresses available over a month; the number online at a given second is smaller, because home devices come and go, which is also what keeps the addresses fresh. For your project the useful number is the pool in your target country and city: send a rotating burst there and count the distinct exits before buying in volume. **How long can I keep the same IP?** Add a session ID and a hold time to the username and the gateway keeps routing you through the same exit for up to 24 hours. If that device goes offline, your next request gets a replacement in the same location and the session continues from there. **How is traffic counted, and does it expire?** You pay for the bandwidth that passes through the gateway, request and response included, measured in GB. The traffic you buy never expires, and the price per GB is set by the highest tier your purchase reaches. **Is there a bandwidth or connection limit?** No. Run as many concurrent connections and sessions as you need; you are only billed for the GB you consume. Projects above 10 TB a month can ask for a custom rate. **How can I test before buying in volume?** Top up the minimum of $20, buy 1 or 2 GB and run your real workload. The traffic you do not use stays on your balance for later, so testing costs nothing extra. **Are residential proxies legal?** Using a proxy is legal in most jurisdictions. What you do through it must be too: our acceptable use policy forbids attacks, fraud, unauthorized access and anything illegal where you or the target operate, and we act on abuse reports. ### ISP proxies **What is an ISP proxy?** An ISP proxy, also called a static residential proxy, is an IP address registered to a consumer internet provider but hosted on datacenter hardware. Websites classify it as a home connection, while you get the speed and uptime of a wired uplink and an address that never changes during your rental. **How is it different from a residential proxy?** Residential proxies route through real household devices and rotate through a pool; you pay per GB and can hold an IP for up to 24 hours. ISP proxies are fixed addresses assigned to you alone for 24 hours to 90 days, with unlimited traffic. Choose residential for breadth and rotation, ISP for stability and volume. **Is traffic really unlimited?** Yes. Nothing is metered on ISP proxies and there is no throttling threshold. You pay per IP for the term; what you send through it is up to you, within the acceptable use policy. **How many ISP IPs are available?** 550K+ static residential addresses across 33 countries, as of September 2026. Unlike a rotating pool, this is inventory: each address is assigned to one customer at a time, so the figure is what orders are drawn from. As the pricing zones reflect, this address space is most abundant in the United States and scarcer elsewhere; availability for the country and city you pick is confirmed when you order. **Can I keep the same IP after the term ends?** Renew before the term expires and the same addresses stay in your list. An IP that expires without renewal returns to inventory and cannot be guaranteed afterwards. **What happens if an IP stops working?** Report it from the dashboard. If the address stays unreachable for more than 24 hours, it is replaced for the remainder of your term at no charge. **Can I choose the city?** Country selection is available everywhere; city selection where the pool in that country allows it, shown at checkout. For city-level precision in every country, residential proxies are the better fit. **Why do prices differ by country?** Because the address space does. ISP-registered blocks are abundant in the United States and scarcer elsewhere, so each region is priced as a group: the United States is the reference, Canada and Western Europe, the rest of Europe, and Asia-Pacific with Brazil follow at published multiples. The group price is shown before you order. **How are the volume discounts applied?** Automatically, on the whole order: 10 IPs or more take 5 % off, 50 or more 10 %, 100 or more 15 %, on top of the term and location price. **Can I test before ordering in volume?** Yes. The 24-hour term lets you try a location from $0.75 per IP in the United States, a little more in other regions, and the $20 minimum top-up covers several of them. ### Datacenter proxies **What is a datacenter proxy?** A datacenter proxy is an IP address hosted in a commercial facility rather than assigned by a consumer ISP. It is the fastest and cheapest proxy type, ideal when the target does not block hosting ranges or when you control both ends. **How does the pooled traffic work?** Every IP in an order adds 100 GB to that order's monthly pool. Usage from any IP draws from the pool, so ten IPs share 1000 GB regardless of which one does the work. The pool resets each monthly cycle. **What happens when the pool runs out?** Speed is reduced until the next cycle so your jobs keep running, or you can add traffic or more IPs from the dashboard at any time. **Are the IPs shared with other customers?** No. Datacenter proxies are dedicated: the addresses in your order belong to you alone for the term. **How many datacenter IPs are available?** 550K+ dedicated addresses in 60+ cities across 37 countries, as of September 2026. This is inventory rather than a rotating pool: an address in your order is yours alone for the term, and the figure is what orders are drawn from, from one IP to thousands in any mix of cities. **Will datacenter IPs work on protected sites?** Often not. Targets that score visitors tend to flag hosting ranges. For those, residential or mobile proxies are the right tool; datacenter IPs shine on volume where trust requirements are low. **Can I choose the city?** Yes. Country, state and city are chosen per IP at checkout from 60+ locations, and one order can mix as many as you like. **Why do prices differ by location?** Bandwidth and colocation cost more in some regions than others. North America is the reference rate; Europe, then Asia-Pacific, the Middle East, Latin America and Africa are priced as groups at published multiples, shown before you order. **How are the volume discounts applied?** Automatically, on the whole order: 10 IPs or more take 5 % off, 50 or more 10 %, 100 or more 15 %, on top of the term and location price. **Can I test a location first?** Yes. Order a single IP on a 30-day term from $0.80 in North America, run your workload and scale the order once it behaves the way you need. ### Mobile proxies **What is a mobile proxy?** A mobile proxy routes your traffic through an IP address assigned by a cellular carrier to a real 4G/5G device. Carriers share each address between thousands of subscribers, so websites treat mobile IPs with far more tolerance than any other kind. **Rotating or dedicated: which should I pick?** Rotating is billed per GB, covers 100+ countries and gives you a new carrier IP on every request or a sticky session: ideal for collection at scale. Dedicated gives you one physical device and its IP for the whole term, with unlimited traffic and rotation on your command: ideal for accounts and anything that must look like one consistent phone. **How large is the mobile pool?** 4.9M+ carrier IP addresses in 100+ countries, as of September 2026, counted as distinct addresses available over a month. A mobile IP is not one device: carriers place many subscribers behind each address, so every IP in the pool stands for a crowd of real phones. That sharing is the reason mobile IPs are so rarely blocked, and why a smaller pool goes further here than on any other network. **How does rotation work on a dedicated device?** You control it. Call the rotation link or API endpoint to get a new IP from the same carrier on demand, or set a timer so the device rotates every few minutes automatically. **Can I choose the carrier?** Yes, where more than one carrier is available in a country. The list per country is shown at checkout for both modes. **Does rotating traffic expire?** No. Like residential, mobile GB stay on your balance until you use them, and the tier you reach applies to the whole purchase. **Is traffic unlimited on dedicated devices?** Yes. A dedicated device is billed per term, not per GB, and there is no throttling threshold. **Why are dedicated devices priced by country?** Each dedicated device is a physical modem with an unlimited carrier plan, hosted and maintained in the country you choose, and plans, hardware and hosting cost very different amounts from one country to another. The United States and Canada are the reference; Western Europe and Australia cost about 20 % less, Eastern Europe, Türkiye, Brazil, South Africa and Asia about half. The exact price for your zone is shown before you order. Rotating traffic, by contrast, costs the same everywhere. **Are mobile proxies slower?** They run at the speed of the cellular network, which is plenty for browsing, apps and most collection jobs, but below a wired datacenter link. For raw throughput, datacenter or ISP proxies are the better fit. **Can I test before committing?** Yes. Buy 2 GB of rotating traffic for $5.24, or a dedicated device for 24 hours from $5.90 depending on the country. ### Comparison **Can I mix networks in one project?** Yes, and most serious pipelines do. One wallet funds all four; residential and mobile share one credential pair on two hostnames, dedicated addresses come with their own. Route by target: datacenter for open sources, residential for scored sites, ISP for accounts, mobile where nothing else passes. **Which network has the largest pool, and does it matter?** Residential, by far: 70M+ addresses, against 4.9M+ on mobile, 550K+ on ISP and 550K+ on datacenter, as of September 2026. Pool size matters where you rotate: the wider the pool in your target country, the less often a target sees the same address twice. On ISP and datacenter it means something else: you rent fixed addresses, so the figure is the inventory your order is drawn from, not something you rotate through. And a mobile address stands for many subscribers behind carrier NAT, so a smaller pool goes further there. **Which network is the cheapest per request?** Datacenter, by a wide margin, wherever the target accepts hosting ranges: a pooled allowance of 100 GB per address each month turns into a fraction of a cent per request. The moment a target blocks hosting ranges, the cheapest network becomes the one whose requests succeed, which is usually residential. **Which is the fastest?** Datacenter and ISP: both sit on wired uplinks in facilities on major exchanges. Residential adds the latency of a household line and mobile that of a cellular network, both fine for pages and APIs, neither meant for bulk transfer. **Do I need mobile proxies for social platforms?** Not always. Many accounts run well on ISP addresses in the account's country, at a fraction of the cost. Mobile becomes the answer when a platform challenges residential-grade addresses, when the audience is mobile-first, or when an account is valuable enough to deserve its own device. **Can I switch networks without changing my code?** Almost. Residential and mobile differ only by hostname. Dedicated addresses are their own ip:port, so a client that reads its proxy from configuration switches by changing one line. Session ids, protocols and authentication behave the same everywhere. **Is one network more private than another?** The gateway behaves the same on all four: it strips proxy headers and adds none, never terminates TLS, and stores what billing and abuse handling require. The difference is on the target side, in how the address is perceived, not in what we see. ## Locations 199 countries and territories have a page under https://proxshift.com/locations. Residential traffic costs the same everywhere; ISP (33 countries), datacenter (37) and dedicated mobile devices (20) are priced by zone. - ISP countries: United States, Canada, United Kingdom, Germany, France, Netherlands, Spain, Italy, Poland, Austria, Belgium, Switzerland, Ireland, Sweden, Denmark, Norway, Finland, Czechia, Portugal, Romania, Lithuania, Latvia, Greece, Hungary, Slovakia, Croatia, Türkiye, Australia, New Zealand, Japan, Singapore, Hong Kong, Brazil - Datacenter countries: United States, Canada, Mexico, Brazil, Argentina, Chile, United Kingdom, Ireland, France, Germany, Netherlands, Belgium, Spain, Portugal, Italy, Switzerland, Austria, Poland, Czechia, Sweden, Norway, Finland, Denmark, Romania, Bulgaria, Türkiye, Israel, United Arab Emirates, India, Singapore, Japan, South Korea, Hong Kong, Taiwan, Australia, New Zealand, South Africa - Dedicated mobile devices: United States, Canada, United Kingdom, Germany, France, Netherlands, Spain, Italy, Austria, Ireland, Australia, Poland, Romania, Bulgaria, Lithuania, Türkiye, Brazil, South Africa, Malaysia, India - City targeting listed for: United States, United Kingdom, Germany, France, Canada, Netherlands, Spain, Italy, Brazil, Japan, Australia, India, Singapore, Poland, Mexico, Türkiye, South Korea, Indonesia, Argentina, South Africa, United Arab Emirates, Sweden, Switzerland, Vietnam, Belgium, Austria, Ireland, Portugal, Czechia, Denmark, Norway, Finland, Romania, Bulgaria, Greece, Hungary, Slovakia, Croatia, Lithuania, Latvia, New Zealand, Hong Kong, Taiwan, Israel, Chile, Malaysia, Philippines, Thailand, Nigeria, Egypt, Saudi Arabia, Colombia, Peru, Ukraine, Pakistan, Bangladesh, Kenya, Morocco, Russia, China ## Company - Trading name: ProxShift; website https://proxshift.com; documentation is the product contract; support through tickets from the account (no public mailbox). - Legal texts: https://proxshift.com/legal/terms, https://proxshift.com/legal/acceptable-use, https://proxshift.com/legal/privacy, https://proxshift.com/legal/refunds - Status: https://proxshift.com/status (JSON: https://proxshift.com/status.json)