A 407 always comes from the proxy, never from the website: the request did not get past the first hop. The response usually carries a Proxy-Authenticate header naming the scheme the proxy expects, typically Basic.

The usual causes

  1. Wrong or missing credentials. Copy the username and password from the order again; a stray space is enough.
  2. Special characters in the password. Inside a proxy URL, @, :, / and # must be percent-encoded, or the client splits the URL in the wrong place. In Python: urllib.parse.quote(password, safe="").
  3. The client never sends them on HTTPS. Some clients drop credentials on the CONNECT request. The JDK does this by default for Basic auth; the Java guide shows the one-line fix.
  4. Your IP left the allowlist. With IP allowlist authentication, a new public IP at home or on a server means the proxy no longer recognises you.

Debug it

Run the request verbosely and look at where the 407 appears:

curl -v -x http://USERNAME:PASSWORD@HOST:PORT "https://api.ipify.org?format=json"

If the output shows a Proxy-Authorization header on the CONNECT line and still gets a 407, the credentials themselves are wrong. If the header is missing, your client or URL is the problem. If you use an allowlist, check your current public address from the same machine without the proxy.

Common confusion

407 is not 401. A 401 comes from the website and means the site wants you to log in; a 407 means the proxy does. And a 403 after a successful tunnel is the website refusing you, not the proxy. The proxy error codes guide sorts every common code by who sent it.