What is a Proxy-Authenticate header?
Sent by a proxy to request authentication from the client, the proxy equivalent of WWW-Authenticate.
Proxy-Authenticate is the proxy-layer equivalent of WWW-Authenticate, sent by an intermediate proxy (rather than the destination website itself) to demand credentials before it will forward the request onward. It's mostly relevant in corporate network setups behind a mandatory authenticated proxy, and rarely something a public website's own server needs to send.
Common use case
A corporate forward proxy responds with 407 and Proxy-Authenticate: Basic to any request that hasn't yet supplied valid proxy credentials, prompting the client to retry with a Proxy-Authorization header.
Example
Proxy-Authenticate: Basic realm="Corporate Proxy"History
Part of the original HTTP/1.1 specification, RFC 2068 (1997), mirroring the design of WWW-Authenticate.
Did you know?
It's one of the few headers a public-facing website's own server will essentially never send - it only makes sense coming from an intermediate proxy, not the final destination.