Java HttpClient proxy setup
Java's built-in HttpClient cannot open TLS to a proxy, so it cannot use the Fixedmark https:// proxy URL. This page shows the HttpClient setup for a plain proxy listener and the planned options for Java apps.
Docs preview: Fixedmark is not live yet. Endpoints are issued at launch, and these pages describe planned launch behavior. Anything marked planned may change. Join early access to get yours first.
The limitation
java.net.http.HttpClient takes a ProxySelector that returns a host and port. It always connects to that address over plain TCP and sends CONNECT in clear text. There is no setting for TLS to the proxy. HttpURLConnection has the same limit.
Your HTTPS traffic to the destination is still encrypted end to end. What is exposed is the Proxy-Authorization header, which carries your app ID and token.
HttpClient setup for a plain listener
A plain HTTP CONNECT listener for clients like Java is planned. Its host and port are not final, so the snippet reads them from env vars.
// Plain HTTP CONNECT listener (planned for clients without HTTPS proxy
// support; host and port not final). Run the JVM with
// -Djdk.http.auth.tunneling.disabledSchemes=
// or HttpClient refuses to send Basic credentials to the proxy.
import java.net.*;
import java.net.http.*;
import java.time.Duration;
public class Main {
public static void main(String[] args) throws Exception {
String host = System.getenv("FIXEDMARK_PROXY_HOST");
int port = Integer.parseInt(System.getenv("FIXEDMARK_PROXY_PORT"));
HttpClient client = HttpClient.newBuilder()
.proxy(ProxySelector.of(new InetSocketAddress(host, port)))
.authenticator(new Authenticator() {
@Override
protected PasswordAuthentication getPasswordAuthentication() {
// Only answer the proxy, never a 401 from the destination.
if (getRequestorType() != RequestorType.PROXY) return null;
return new PasswordAuthentication(
System.getenv("FIXEDMARK_APP_ID"),
System.getenv("FIXEDMARK_TOKEN").toCharArray());
}
})
.connectTimeout(Duration.ofSeconds(10))
.build();
HttpRequest req = HttpRequest.newBuilder(
URI.create("https://api.partner.example/v1/orders")).build();
HttpResponse<String> res =
client.send(req, HttpResponse.BodyHandlers.ofString());
System.out.println(res.statusCode());
}
}The Authenticator checks getRequestorType(). Without that check it would also answer a 401 from the destination with your Fixedmark token.
Basic auth for tunnels
The JDK disables Basic authentication for HTTPS tunnels by default through the jdk.http.auth.tunneling.disabledSchemes property. With the default, HttpClient never sends your credentials and you get 407. Set the property to an empty value on the command line, or in JAVA_TOOL_OPTIONS on platforms where you cannot change the start command.
Options for Java
- Plain HTTP listener (planned). Works with HttpClient as shown. Give the token a destination allowlist so a leaked credential can only reach the APIs you list.
- bm tunnel (planned). Forwards a local port to a remote host through your static IPs over TLS. It suits databases and fixed TCP endpoints. See the bm tunnel reference.
- SOCKS5.
java.net.Socketand many JDBC drivers can use SOCKS5, but SOCKS5 credentials are also unencrypted, and HttpClient does not support SOCKS proxies.
JDBC drivers
Drivers built on java.net.Socket follow the JVM-wide socksProxyHost and socksProxyPort properties. Those properties apply to every socket in the JVM, not only the database. For a single database connection, the planned bm tunnel is the cleaner option. See databases.
407 through a plain CONNECT proxy until Basic tunneling was re-enabled, then succeeded. It could not connect to the TLS-wrapped proxy port.Platform guides
Frequently asked questions
Can Java HttpClient use an HTTPS proxy?
No. java.net.http.HttpClient connects to proxies over plain TCP only. It cannot open TLS to a proxy, so it cannot use an https:// proxy URL.
Why does Java HttpClient return 407 even with an Authenticator?
Since Java 8u111 the JDK disables Basic authentication for HTTPS tunnels by default. Start the JVM with -Djdk.http.auth.tunneling.disabledSchemes= (empty) to allow it.
What is the best option for Java at launch?
For databases, the planned bm tunnel CLI. For HTTP APIs, the planned plain HTTP listener with a destination-restricted token. Both are not final yet.
Make it fixed.
Fixedmark is in early access. Join the list to get dedicated static IPs when your region opens.