What is a Proxy-Authorization header?
Carries credentials to authenticate the client with a proxy server, the proxy equivalent of Authorization.
Proxy-Authorization is Authorization's counterpart for authenticating with a proxy server sitting in front of the actual destination, rather than the destination website itself. It's mostly relevant in corporate or ISP network setups with a mandatory authenticated proxy, and rarely something a public-facing website's own monitoring needs to worry about.
Common use case
A corporate laptop configured to route all traffic through a mandatory authenticating proxy attaches Proxy-Authorization with the employee's proxy credentials on every outbound request.
Example
Proxy-Authorization: Basic dXNlcjpwYXNzd29yZA==History
Part of the original HTTP/1.1 specification, RFC 2068 (1997), mirroring the design of the destination-facing Authorization header.
Did you know?
It's scoped strictly to the proxy - a client can legitimately send both this and a regular Authorization header on the same request, authenticating separately with the proxy and the final destination.