Skip to content
Draft
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
5 changes: 3 additions & 2 deletions auth/configuration.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -213,9 +213,10 @@ Pin the auth flow to a specific [proxy](/proxies/overview) so logins, health che

How stable the exit IP is depends on the proxy type:

- **[ISP](/proxies/isp)** and **[datacenter](/proxies/datacenter)** proxies provide a stable exit IP within a single session, but Kernel does not guarantee the same IP across sessions. Sites with adaptive auth that trigger a step-up challenge (one-time code, device verification) when the client IP changes may flag the IP shift between the initial login and a subsequent health check or reauth.
- **[ISP](/proxies/isp)** proxies have a static exit IP that persists across sessions, so the initial login, every health check, and every reauth egress through the same IP. The IP only changes in rare ISP-initiated replacement events. Each ISP proxy gets its own IP, so reuse the same proxy rather than creating a new one.
- **[Datacenter](/proxies/datacenter)** proxies rotate exit IPs per request. Sites with adaptive auth that trigger a step-up challenge (one-time code, device verification) when the client IP changes may flag the IP shift between the initial login and a subsequent health check or reauth.
- **[Residential](/proxies/residential)** proxies rotate IPs per connection — use them when you need legitimacy from a real ISP pool but can tolerate IP changes.
- **[Custom (BYO)](/proxies/custom)** proxies route through whatever you point them at, so this is the right pick if you need a truly static IP that persists across the initial login and every subsequent health check and reauth (e.g. an allowlisted egress your security team owns).
- **[Custom (BYO)](/proxies/custom)** proxies route through whatever you point them at, so this is the right pick if you need to control the egress IP yourself (e.g. an allowlisted egress your security team owns).

Create a proxy first, then attach it to the connection:

Expand Down
Loading