# Trusted IPs

> Connect from a trusted IP without a password, and keep targeting by sending your username with an empty password.

Source: https://docs.trueproxies.com/proxy-instructions/trusted-ips/

A trusted IP authenticates a connection by its public source address. Add an address to a service and connections from it are accepted without a password. Your username and password keep working alongside any trusted IPs.

## Add a trusted IP

1. ### Find the address you will connect from

   Run this on the machine that will open the proxy connections:

   ```bash
   curl https://httpbin.org/ip
   ```

2. ### Add it to the service

   Open the service in the dashboard, go to its **Trusted IPs** tab and choose **Add trusted IP**. Each IP can be trusted by one service at a time.

3. ### Connect to the same host and ports

   A trusted IP uses the service’s usual **Connection host** and ports. There are no separate endpoints for trusted IPs.

## Connecting

Send no credentials at all to connect without targeting:

```bash
curl -x http://YOUR_HOST:YOUR_HTTP_PORT \
  https://httpbin.org/ip
```

## Targeting without a password

Targeting travels on the username. To keep country, city, region, ASN or session targeting from a trusted IP, send your username with its options and leave the password empty:

```bash
curl -x http://YOUR_HOST:YOUR_HTTP_PORT \
  -U "YOUR_USERNAME-session-ab12cd-country-de:" \
  https://httpbin.org/ip
```

The username must be the service’s own username from its **Username and password** tab, followed by the options from [How to connect](https://docs.trueproxies.com/proxy-instructions/how-to-connect/#options). A trusted IP admits connections only to the service that trusts it.

The same works for SOCKS5 clients that offer a username but no password:

```bash
curl --socks5-hostname YOUR_HOST:YOUR_SOCKS_PORT \
  --proxy-user "YOUR_USERNAME-country-de:" \
  https://httpbin.org/ip
```

> **Note**
>
> Sending your proxy password with the username uses normal password authentication, from any address, and the password must be correct. A trusted IP only admits connections that send no password.

## Choosing between the two

A trusted IP keeps your proxy password off the network you connect from — worth having on the plain `http` and `socks5` ports, where credentials would otherwise travel in clear text. It requires a stable address.

Password authentication works from anywhere, which is what you want from a laptop, a dynamic connection, or anywhere you cannot pin an address.

Both work at once, so you can use whichever suits each machine.

> **Caution**
>
> A trusted IP trusts every process that can reach the internet through that address, including anything else on the same network. Use a stable, controlled source, and remove addresses you no longer use.
