← All headersRequest header

What is a Proxy-Authorization header?

Carries credentials to authenticate the client with a proxy server, the proxy equivalent of Authorization.

Proxy-Authorization is Authorization's counterpart for authenticating with a proxy server sitting in front of the actual destination, rather than the destination website itself. It's mostly relevant in corporate or ISP network setups with a mandatory authenticated proxy, and rarely something a public-facing website's own monitoring needs to worry about.

Common use case

A corporate laptop configured to route all traffic through a mandatory authenticating proxy attaches Proxy-Authorization with the employee's proxy credentials on every outbound request.

Example

Proxy-Authorization: Basic dXNlcjpwYXNzd29yZA==

History

Part of the original HTTP/1.1 specification, RFC 2068 (1997), mirroring the design of the destination-facing Authorization header.

Did you know?

It's scoped strictly to the proxy - a client can legitimately send both this and a regular Authorization header on the same request, authenticating separately with the proxy and the final destination.