HTTP 407 Proxy Authentication Required
A proxy between you and the server requires credentials before it will forward your request.
Meaning
407 is like 401 but for a proxy (often a corporate proxy). The proxy returns a Proxy-Authenticate header; the client must resend with Proxy-Authorization. Command-line tools (npm, git, pip, curl) commonly hit this inside company networks.
Common causes
- Corporate proxy requires a username/password or NTLM/Kerberos auth
- Proxy credentials expired or password changed
- Tool not configured to use the proxy credentials (npm, git, pip, Docker)
- Special characters in the password not URL-encoded in the proxy URL
⚡ Quick fix
- Set
HTTP_PROXY/HTTPS_PROXYwith credentials:http://user:pass@proxy:8080 - URL-encode special characters in the password (
@→%40) - Configure each tool:
npm config set proxy …,git config --global http.proxy … - For NTLM proxies, run a local helper like Cntlm or Px
Detailed fix by platform
Linux
- Environment variables used by most CLIs:bash
export HTTP_PROXY="http://user:p%40ss@proxy.corp:8080" export HTTPS_PROXY="$HTTP_PROXY" export NO_PROXY="localhost,127.0.0.1,.corp.local"
npm
npm config set proxy http://user:pass@proxy:8080andnpm config set https-proxy ….
Git
git config --global http.proxy http://user:pass@proxy:8080.
How to diagnose
- Network — Are you behind a corporate proxy or VPN?
- Tool config — Does this tool read HTTP(S)_PROXY or need its own config?
- Credentials — Are they current and URL-encoded?
- Auth type — Does the proxy require NTLM/Kerberos instead of Basic?
🧠 Still stuck? Analyze your error
Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.
Was this page helpful?
Report a correction or suggest an improvement
Last updated 2 Oct 2026