Protocols
Every port speaks HTTP and SOCKS5, the protocol is detected by the first byte of the connection. Clients authenticate with proxy accounts from the database, inactive and expired ones are refused:
curl -x http://127.0.0.1:8080 --proxy-header "Proxy-Authorization: Bearer <token>" https://example.com # token accountHTTP supports CONNECT tunnels and plain HTTP forwarding. SOCKS5 supports only CONNECT, with IPv4, IPv6 and domain targets, and only basic accounts: the protocol has username/password authentication but no tokens.
Clients from trusted networks connect without credentials. To encrypt the connection to the proxy, see TLS.