Static IP proxy quickstart
Set FIXEDMARK_PROXY_URL in your app's environment and pass it as the proxy for your HTTP client. Outbound requests then leave from your static IP pair. Use SOCKS5 or bm tunnel for databases.
Docs preview: Fixedmark is not live yet. Endpoints are issued at launch, and these pages describe planned launch behavior. Anything marked planned may change. Join early access to get yours first.
How it works
Fixedmark runs an outbound proxy in each region. Your app opens a TLS connection to the proxy and asks it to connect to the destination. The proxy makes that connection from one of your two static IPv4 addresses. The destination sees your Fixedmark IP, not your platform's changing IP.
For HTTPS destinations the proxy only relays encrypted bytes. It never decrypts your traffic. Read concepts for the details.
1. Set the environment variables
Add the proxy URLs to your platform's environment variables or secrets. Keep them out of source control. APP_ID and TOKEN come from the dashboard at launch.
FIXEDMARK_PROXY_URL=https://APP_ID:TOKEN@mum.egress.fixedmark.com:443
FIXEDMARK_SOCKS_URL=socks5h://APP_ID:TOKEN@mum.egress.fixedmark.com:1080If the token contains @, :, or /, URL-encode it. Setting HTTPS_PROXY for the whole process also works with many clients. It sends every outbound request through the proxy, so every request counts against your plan. Prefer passing the URL only to the clients that need a static IP.
2. Send a request through the proxy
Each snippet sends one request through your static IPs. HTTPS stays encrypted end to end inside the CONNECT tunnel.
# curl 7.52+ supports an https:// proxy URL
curl --proxy "$FIXEDMARK_PROXY_URL" https://api.partner.example/v1/orders// npm install undici (undici 8 needs Node.js 22.19+)
import { fetch, ProxyAgent } from "undici";
// Create one agent and reuse it. It keeps connections to the proxy open.
const proxy = new ProxyAgent(process.env.FIXEDMARK_PROXY_URL);
const res = await fetch("https://api.partner.example/v1/orders", { dispatcher: proxy });
console.log(res.status, await res.json());# pip install requests (needs urllib3 1.26+ for an https:// proxy URL)
import os
import requests
proxy = os.environ["FIXEDMARK_PROXY_URL"]
# Pass proxies per request. On a Session, HTTPS_PROXY in the
# environment overrides session.proxies.
proxies = {"http": proxy, "https": proxy}
res = requests.get("https://api.partner.example/v1/orders", proxies=proxies, timeout=15)
print(res.status_code, res.json())package main
import (
"fmt"
"log"
"net/http"
"net/url"
"os"
"time"
)
func main() {
proxyURL, err := url.Parse(os.Getenv("FIXEDMARK_PROXY_URL"))
if err != nil {
log.Fatal(err)
}
// Build one client and reuse it so connections are pooled.
client := &http.Client{
Transport: &http.Transport{
Proxy: http.ProxyURL(proxyURL),
MaxIdleConnsPerHost: 10,
IdleConnTimeout: 90 * time.Second,
},
Timeout: 15 * time.Second,
}
res, err := client.Get("https://api.partner.example/v1/orders")
if err != nil {
log.Fatal(err)
}
defer res.Body.Close()
fmt.Println(res.Status)
}Full guides with version notes: Node.js, Python, Go, Ruby, PHP, Java, and Deno and Bun. Your client must support an https:// proxy URL. Most current clients do. Java's built-in client and Ruby's Net::HTTP do not, and their guides explain the options.
3. Allowlist both IPs
Your plan includes a pair of IPv4 addresses. Add both to every allowlist: the partner API, the database firewall, or the broker portal. Traffic can leave from either IP, and failover moves traffic between them. If you allowlist only one, about half of your connections fail.
4. Verify the egress IP
Call the Fixedmark IP endpoint through the proxy. It returns the IP the destination sees, which should be one of your pair.
# Plain text: prints the IP the destination sees.
curl --proxy "$FIXEDMARK_PROXY_URL" https://fixedmark.com/api/ip
# JSON: {"ip":"203.0.113.10","version":4}
curl --proxy "$FIXEDMARK_PROXY_URL" -H "Accept: application/json" https://fixedmark.com/api/ipWithout the proxy, https://fixedmark.com/api/ip shows your app's own egress IP. See verify your egress IP for checks from code and from the database side.
Databases and other TCP
Database drivers do not speak HTTP CONNECT. Use the SOCKS5 URL when the driver can dial through SOCKS5. Otherwise run the planned bm tunnel CLI, which forwards a local port to the database through your static IPs. See databases and the bm tunnel reference.
All docs
- ConceptsHow the Fixedmark static IP proxy works: IP pairs and failover, regions, tokens, the TLS proxy endpoint, CONNECT tunnels, and socks5 versus socks5h DNS.
- Verify egress IPCheck which IP a destination sees by calling fixedmark.com/api/ip through your proxy with curl, Node, or Python, and confirm the database sees your IP pair.
- Node.jsRoute Node.js requests through a static IP: undici ProxyAgent, EnvHttpProxyAgent, NODE_USE_ENV_PROXY, axios with an HTTPS proxy, and SOCKS5 agents.
- PythonSend Python requests through a static IP with an HTTPS proxy URL: requests, httpx, and aiohttp snippets, version notes, SOCKS5, and environment variables.
- GoRoute Go net/http requests through a static IP with http.Transport Proxy, an HTTPS proxy URL, or socks5h, plus a SOCKS5 dialer for database drivers.
- RubySend Ruby requests through a static IP: Typhoeus with an HTTPS proxy URL, why Net::HTTP and Faraday fail through a TLS proxy today, and planned fallbacks.
- PHPRoute PHP requests through a static IP with an HTTPS proxy URL in Guzzle or the cURL extension. Check libcurl HTTPS proxy support and set timeouts.
- JavaUse a static IP proxy from Java: HttpClient with ProxySelector and Basic auth, why it cannot use an HTTPS proxy endpoint, and the planned workarounds.
- Deno and BunProxy fetch through a static IP in Deno with Deno.createHttpClient and in Bun with the fetch proxy option, including SOCKS5 and environment variables.
- DatabasesConnect Postgres, MySQL, MongoDB, and Redis to IP allowlists through a static IP with SOCKS5 dialers or bm tunnel, with TLS and pooling notes per driver.
- bm tunnel CLIPlanned reference for the bm tunnel CLI: port-forward syntax, transparent mode, the local config file, running it beside your app, and what is not final.
- TroubleshootingFix static IP proxy errors: 407 auth failures, 403 destination not allowed, TLS errors to the proxy, timeouts, DNS leaks, connection resets, and quotas.
- Limits and securityPlanned limits for the Fixedmark proxy: request and bandwidth quotas, soft limits, rate limits, idle timeouts, blocked ports, and how traffic is protected.
Other references: features, security, regions, and planned pricing.
Platform guides
Frequently asked questions
How do I route my app's traffic through a static IP?
Set FIXEDMARK_PROXY_URL in your app's environment, then pass it as the proxy for the HTTP client that calls the allowlisted API. Those requests then leave from your Fixedmark IP pair.
Do I need to allowlist both IPs?
Yes. Each new connection can leave from either IP in the pair, and failover moves traffic between them. Add both IPs to every allowlist.
Should I use the HTTPS proxy or SOCKS5?
Use the HTTPS proxy URL for HTTP APIs. Use SOCKS5 or the planned bm tunnel CLI for databases, SSH, SFTP, and other TCP protocols.
Can I use Fixedmark from Cloudflare Workers?
Not at launch. The Workers fetch API has no proxy option. See the Cloudflare Workers integration page for the current status.
Where do I get my proxy URL?
Proxy endpoints are issued at launch. Join early access to get yours first.
Make it fixed.
Fixedmark is in early access. Join the list to get dedicated static IPs when your region opens.