Static outbound IP proxy features
Fixedmark gives your serverless or PaaS app a pair of static outbound IPs through one proxy URL. It supports HTTP CONNECT over TLS, SOCKS5, and a tunnel CLI, with connection logs and per-token destination allowlists. Nothing is live yet: each feature below is marked as planned for launch or on the roadmap.
Available at launch
Planned for the first public version.
- Available at launch
Dedicated IP pairs
Two static IPv4 addresses reserved for your account only, load-balanced for high availability. Allowlist both once.
- Available at launch
HTTP, HTTPS, and SOCKS5 in one plan
HTTP CONNECT for APIs and SOCKS5 for databases, SSH, and any TCP service. One subscription, one set of IPs.
- Available at launch
Zero-knowledge by default
TLS passes through end to end and is never decrypted. A TLS-wrapped proxy endpoint keeps your proxy credentials off the wire in cleartext.
- Available at launch
India and Asia regions
Mumbai, Chennai, and Bangalore, plus Singapore, Jakarta, Tokyo, Sydney, Frankfurt, and the US, for low latency to Indian bank, broker, and partner APIs.
- Available at launch
Connection logs
See destination, SNI, bytes, egress IP, and result for every connection, so allowlist errors are easy to debug.
- Available at launch
Destination allowlists
Restrict each token to the hosts and ports it needs, such as api.razorpay.com:443. A leaked token cannot reach anything else.
- Available at launch
bm tunnel CLI
Forward local ports to IP-restricted databases for drivers without proxy support. Works from a local config file with no startup API call.
- Available at launch
Usage alerts and webhooks
Soft limits with alerts before you hit them, plus webhooks for quota and IP health events.
On the roadmap
Planned after launch, in rough priority order.
- On the roadmap
Inbound static IP
Give partners a fixed address to reach your app, with TCP and SNI passthrough.
- On the roadmap
Multi-region failover
Allowlist IPs in two regions and fail over automatically if a region goes down.
- On the roadmap
Terraform provider and public API
Manage endpoints, IPs, and tokens as code alongside the rest of your infrastructure.
- On the roadmap
IPv6 egress and WireGuard
IPv6 egress at no extra cost and a WireGuard tunnel for whole-network routing.
Protocols and clients
Every plan includes HTTP and SOCKS5 on the same IPs, so you do not need separate subscriptions. Paid plans add the bm tunnel CLI.
HTTP CONNECT on a TLS endpoint
Set one HTTPS proxy URL. Your client opens TLS to the proxy, then a CONNECT tunnel to the destination. Proxy credentials never cross the internet in cleartext.
SOCKS5
For databases, SSH, SFTP, and any TCP service. Use socks5h:// so DNS resolves on the proxy side.
bm tunnel CLI
Port-forward mode maps a local port to a remote host, such as 5432:db.example.com:5432. Transparent mode routes traffic for named hosts with no code changes.
Local config file
The CLI reads its routes and token from a local config file. It does not call a Fixedmark API at startup, so a control-plane outage cannot stop your app from booting.
Code for each language is in the docs quickstart.
How it works
Each region runs a pair of proxy nodes. Each node owns one of your two static IPs and sends traffic from it.
Health checks run against both nodes. If a node fails, its IP moves to the healthy node. Traffic keeps leaving from the same two addresses, so your allowlist entries stay valid.
IPs are tracked separately from servers. When a node is replaced, the IP moves to the new node. It is never swapped for a new address.
Your IPs live in one region. Multi-region failover is on the roadmap. See launch regions for details.
- 1Your app (Vercel, Railway, Supabase, ...)
- 2Proxy URL over TLS, or SOCKS5
- 3Region: node A + node B, health-checked
- 4Egress from IP 1 or IP 2 (IP failover between nodes)
- 5Partner API or database allowlists both IPs
What Fixedmark does not do
- No rotating or residential proxies. Fixed IPs only.
- No scraping. Abuse on one account can harm IP reputation for everyone else.
- No outbound SMTP on the free plan.
- No decryption of your TLS traffic, on any plan.
More on this on the security page.
Works with your platform
Setup guides for each platform:
Frequently asked questions
What does a static outbound IP proxy do?
It sends your app's outbound requests through servers with fixed public IP addresses. The API or database you call sees the same IP pair every time, so you can add those IPs to its allowlist once, even when your app runs on serverless functions with changing IPs.
Is the IP pair shared with other customers?
On the planned Free and Starter plans the IP pair is shared. From the Pro plan up, the pair is dedicated to your account and no other customer sends traffic from it.
Can Fixedmark read my HTTPS traffic?
No. HTTP CONNECT and SOCKS5 pass your TLS connection through end to end. Fixedmark sees the destination host, port, TLS SNI, and byte counts, never the request or response content.
How do I use Fixedmark with a database that has no proxy support?
Use SOCKS5 if your driver supports it. If it does not, run bm tunnel (planned for paid plans) to forward a local port to the database through your static IPs, for example bm tunnel 5432:db.example.com:5432.
What happens if one node in a region fails?
Each region runs a pair of health-checked nodes. If one fails, its IP moves to the healthy node, so traffic keeps leaving from the same IP addresses you allowlisted.
Which features are available today?
None yet. Fixedmark is in development with an early-access list. Features marked Available at launch are planned for the first public version. Roadmap items come after launch.
Make it fixed.
Fixedmark is in early access. Join the list to get dedicated static IPs when your region opens.