Proxy providers

Proxy Bastion does not sell IPs. It takes upstreams you already pay for and hands other people a revocable, metered link instead of your credentials. These pages are the per-provider setup recipes.

Where a page states a gateway host, port or credential format, we read it off that provider's own public documentation and list the source and the date at the bottom of the page. Where we could not confirm a value, the page says so instead of guessing.

Every provider below is used over http or https. socks5 upstreams are not supported in this release.

  • Oxylabs
    Put an Oxylabs upstream behind links that expire and meter traffic, so the people using it never hold your credentials. http and https upstreams only, not socks5.
  • Bright Data
    Wrap a Bright Data upstream in per-recipient links with an expiry and a traffic cap, so revoking one person does not mean rotating credentials for everyone. http and https upstreams only, not socks5.
  • Decodo
    Put a Decodo upstream behind links that expire and meter traffic, so nobody you share with ever holds your credentials. http and https upstreams only, not socks5.
  • IPRoyal
    Wrap an IPRoyal upstream in per-recipient links that expire and meter traffic, so you can cut one person off without rotating anything. http and https upstreams only, not socks5.
  • Webshare
    Put a Webshare upstream behind per-recipient links with an expiry and a traffic cap. Also covers a trap: the token in their API docs is not the proxy password. http and https upstreams only, not socks5.
  • PacketStream
    Turn a PacketStream residential gateway into per-person links with an expiry and a traffic cap. Recipients never see the username or password. http and https upstreams only, not socks5.
  • Proxy-Cheap
    Put a Proxy-Cheap residential or static proxy behind per-person links with an expiry and a traffic ceiling. Recipients never see the host or the password. http and https upstreams only, not socks5.
  • DataImpulse
    Wrap a DataImpulse upstream in per-recipient links with an expiry and a traffic cap. Covers the split between credential and IP-allowlist authentication, which changes what you can share. http and https upstreams only, not socks5.