Skip to content

Datacenter IPv6

Datacenter IPv6 gives you a private /48 in the city you buy. The gateway draws a fresh IPv6 from that subnet for each new connection unless you provide a session token.

AddressesA private /48 for the purchased city
Default behaviourA new IPv6 on every new connection
Sticky sessionsOpt in with a session token; 10 minutes by default, 60 seconds to 24 hours with lifetime
CitySelected when the service is purchased
ProtocolsHTTP 8080, HTTPS 8443, and SOCKS5 1080 on the service’s connection host
AuthenticationUsername and password, and trusted IPs, together
BillingSpeed tier; no per-GB charge; published fair-use limit

Datacenter IPv6 connection hosts are city specific. The dashboard is the source of truth for a purchased service’s host and credentials; the ports are the same as on every other product. Do not append :443 to the host.

You reach the connection host over IPv4, so the machine running your client does not need IPv6. Only the exit your target sees is IPv6.

To check the exit, use an IPv6-capable target such as https://api64.ipify.org. An IPv4-only destination cannot be reached through an IPv6-native exit.

Choose 25, 70, 175, or 400 Mbps, then choose a daily, weekly, or monthly plan. Every tier publishes its fair-use limit in the catalog.

Nothing is charged automatically. Before a plan ends, we send a renewal invoice: 12 hours before for daily plans, and 3 days before for weekly and monthly plans. Paying it extends the plan from its current end date; if it is not paid, the plan ends. You can turn renewal invoices off for each service in the dashboard.

Daily plans are non-refundable. Weekly and monthly plans are refundable only for a verified technical issue on our side; see the refund policy.

Rotation happens per connection, not per HTTP request. A client that reuses a keep-alive connection keeps its address for that connection; open a new one and the gateway selects a fresh address.

  • HTTP — a new address whenever a new upstream connection is opened.
  • HTTPS / CONNECT and SOCKS5 TCP — one address per tunnel.
  • SOCKS5 UDP — not supported. UDP requests are refused; SOCKS5 carries TCP only.

Add a session token and every connection carrying it leaves from the same address for a fixed time window. Without a lifetime the window is 10 minutes. To change it, add a lifetime in seconds, from 60 to 86400:

YOUR_USERNAME-session-checkout42-lifetime-3600:YOUR_PASSWORD

Windows follow the clock, not your first connection. With lifetime-600 the address changes at every 10-minute boundary, so a session that starts two minutes before a boundary keeps its address for two minutes. Choose a lifetime longer than the job, or use a new session token when the address must not change mid-task.

The city is selected when you buy the service. Its connection host applies to that city; do not attempt to switch cities by adding a credential suffix. Buy a service for the city you need instead.

Both authentication methods work at once on every port. Trusted IPs can connect without a password; everyone else uses username and password.

If a password is sent, it must be correct. A trusted IP does not excuse a wrong password because that would silently downgrade authentication.

OptionValue
session1–32 letters or digits
lifetimeWindow length in seconds, 60 to 86400; omit for 10 minutes
rotateThe default; accepted and changes nothing

Unsupported selectors such as city, region, continent, isp, asn, zip, and fraud or device selectors are refused with the same answer as any invalid targeting option; the message does not name the selector.

The service’s page in the dashboard shows its city, connection host and ports, and access dates. To automate, use the API page in your dashboard, where you create API keys and open the API reference.