Skip to content

Clarify proxy exit IP stability across sessions - #669

Merged
aylee855 merged 2 commits into
mainfrom
hypeship/clarify-proxy-ip-stability
Oct 5, 2026
Merged

aylee855 merged 2 commits into
mainfrom
hypeship/clarify-proxy-ip-stability

Conversation

@aylee855

@aylee855 aylee855 commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

Summary

The docs gave conflicting answers about whether a proxy's exit IP stays the same across sessions. This makes them consistent with the ISP and datacenter proxy pages and with how the API selects IPs.

  • Managed auth → Custom Proxy (auth/configuration.mdx): this section said ISP and datacenter proxies are only stable within a session. That contradicted the ISP page, which says the IP persists across sessions, and the datacenter page, which says the IP changes per request. The two are now separate bullets with the correct behavior. The custom (BYO) bullet now positions custom proxies for cases where the static IP has to be infrastructure you control, since ISP already gives a static IP.
  • Stealth mode (browsers/bot-detection/stealth.mdx): the default stealth proxy was described as "a static ISP proxy", which reads like a dedicated ISP proxy. The page now says it comes from a shared pool: stable within a session, but a new session may get a different IP. It also tells readers to create an ISP proxy and attach it if they need the same IP across sessions.
  • ISP proxies (proxies/isp.mdx): adds a "Backup endpoint failover" section. For some organizations, an ISP proxy carries a backup endpoint from a different provider. If the primary endpoint refuses connections, traffic temporarily exits through the backup IP, then returns to the primary. The proxies overview and the managed auth ISP bullet link to it as the second case where the IP can change.
  • Bot detection overview (browsers/bot-detection/overview.mdx): same wording fix for stealth. The ISP paragraph now says the static IP holds across sessions attached to the proxy, not just within one session.

How the behavior was verified

Checked against the API source:

  • Default stealth proxy: chosen per browser instance by hashing {instance_name}-{metro} into the region's shared ISP list (pingproxy.GetIspProxyForStableKey, called from getDefaultStealthProxyConfig and the egress-proxy DefaultStealthResolver). Instance names include random cuid2s, so each new browser can land on a different IP.
  • User-created ISP proxy: host and credentials are picked once at create time and stored on the proxy's binding (applyISP). Every session attached to the proxy reuses that binding.
  • ISP backup endpoint: a second binding from the other provider is attached when ISP fallback is enabled for the org and country (ISPFallbackEnabled, ensureISPFallback). Egress-proxy routes a request to it only when the primary endpoint refuses the TCP dial, and caches the primary as unhealthy for 30s (isp_fallback.go in metro-api egressproxy). The docs say "some organizations" without naming the eligibility config.

Testing

mint broken-links passes. I didn't run the local preview.

🤖 Generated with Claude Code


Note

Low Risk
Documentation-only wording and cross-links; no runtime or API behavior changes.

Overview
Aligns proxy exit-IP behavior across managed auth, stealth, and proxy docs so readers no longer see ISP/datacenter described as “stable only within a session.”

In managed auth Custom Proxy, ISP and datacenter are split into separate bullets: user-created ISP proxies keep a static IP across sessions (with rare replacement or temporary backup failover); datacenter gets a new IP per request. Custom (BYO) is reframed for when the static egress must be infrastructure you control.

Stealth and bot-detection overview now describe the default proxy as an ISP from a shared Kernel pool—stable within a session, but a new session may use a different IP—and point readers to create an ISP proxy and attach proxy_id for cross-session stability.

ISP proxies gains a Backup endpoint failover subsection; proxies overview and the auth ISP bullet link to it as a second case where the allowlisted IP can briefly change.

Reviewed by Cursor Bugbot for commit 492a29c. Bugbot is set up for automated code reviews on this repo. Configure here.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@mintlify

mintlify Bot commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

Preview deployment for your docs. Learn more about Mintlify Previews.

Project Status Preview Updated
Kernel 🟢 Ready View Preview Oct 5, 2026, 7:23 PM

💡 Tip: Enable Automations to automatically generate PRs for you.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@aylee855
aylee855 marked this pull request as ready for review October 5, 2026 19:26

@sjmiller609 sjmiller609 left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed carefully. All looks good to me.

@aylee855
aylee855 merged commit ef57696 into main Oct 5, 2026
3 checks passed
@aylee855
aylee855 deleted the hypeship/clarify-proxy-ip-stability branch October 5, 2026 19:48

This branch was successfully deployed

1 active deployment
staging — 492a29c4 Deployed Oct 5, 2026 by mintlify[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants