Skip to content
Fixedmark
Docs

Static IP proxy quickstart

Set FIXEDMARK_PROXY_URL in your app's environment and pass it as the proxy for your HTTP client. Outbound requests then leave from your static IP pair. Use SOCKS5 or bm tunnel for databases.

Docs preview: Fixedmark is not live yet. Endpoints are issued at launch, and these pages describe planned launch behavior. Anything marked planned may change. Join early access to get yours first.

How it works

Fixedmark runs an outbound proxy in each region. Your app opens a TLS connection to the proxy and asks it to connect to the destination. The proxy makes that connection from one of your two static IPv4 addresses. The destination sees your Fixedmark IP, not your platform's changing IP.

For HTTPS destinations the proxy only relays encrypted bytes. It never decrypts your traffic. Read concepts for the details.

1. Set the environment variables

Add the proxy URLs to your platform's environment variables or secrets. Keep them out of source control. APP_ID and TOKEN come from the dashboard at launch.

FIXEDMARK_PROXY_URL=https://APP_ID:TOKEN@mum.egress.fixedmark.com:443
FIXEDMARK_SOCKS_URL=socks5h://APP_ID:TOKEN@mum.egress.fixedmark.com:1080

If the token contains @, :, or /, URL-encode it. Setting HTTPS_PROXY for the whole process also works with many clients. It sends every outbound request through the proxy, so every request counts against your plan. Prefer passing the URL only to the clients that need a static IP.

2. Send a request through the proxy

Each snippet sends one request through your static IPs. HTTPS stays encrypted end to end inside the CONNECT tunnel.

# curl 7.52+ supports an https:// proxy URL
curl --proxy "$FIXEDMARK_PROXY_URL" https://api.partner.example/v1/orders

Full guides with version notes: Node.js, Python, Go, Ruby, PHP, Java, and Deno and Bun. Your client must support an https:// proxy URL. Most current clients do. Java's built-in client and Ruby's Net::HTTP do not, and their guides explain the options.

3. Allowlist both IPs

Your plan includes a pair of IPv4 addresses. Add both to every allowlist: the partner API, the database firewall, or the broker portal. Traffic can leave from either IP, and failover moves traffic between them. If you allowlist only one, about half of your connections fail.

4. Verify the egress IP

Call the Fixedmark IP endpoint through the proxy. It returns the IP the destination sees, which should be one of your pair.

# Plain text: prints the IP the destination sees.
curl --proxy "$FIXEDMARK_PROXY_URL" https://fixedmark.com/api/ip

# JSON: {"ip":"203.0.113.10","version":4}
curl --proxy "$FIXEDMARK_PROXY_URL" -H "Accept: application/json" https://fixedmark.com/api/ip

Without the proxy, https://fixedmark.com/api/ip shows your app's own egress IP. See verify your egress IP for checks from code and from the database side.

Databases and other TCP

Database drivers do not speak HTTP CONNECT. Use the SOCKS5 URL when the driver can dial through SOCKS5. Otherwise run the planned bm tunnel CLI, which forwards a local port to the database through your static IPs. See databases and the bm tunnel reference.

All docs

Other references: features, security, regions, and planned pricing.

Platform guides

Frequently asked questions

How do I route my app's traffic through a static IP?

Set FIXEDMARK_PROXY_URL in your app's environment, then pass it as the proxy for the HTTP client that calls the allowlisted API. Those requests then leave from your Fixedmark IP pair.

Do I need to allowlist both IPs?

Yes. Each new connection can leave from either IP in the pair, and failover moves traffic between them. Add both IPs to every allowlist.

Should I use the HTTPS proxy or SOCKS5?

Use the HTTPS proxy URL for HTTP APIs. Use SOCKS5 or the planned bm tunnel CLI for databases, SSH, SFTP, and other TCP protocols.

Can I use Fixedmark from Cloudflare Workers?

Not at launch. The Workers fetch API has no proxy option. See the Cloudflare Workers integration page for the current status.

Where do I get my proxy URL?

Proxy endpoints are issued at launch. Join early access to get yours first.

Make it fixed.

Fixedmark is in early access. Join the list to get dedicated static IPs when your region opens.