Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
5 changes: 3 additions & 2 deletions auth/configuration.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -213,9 +213,10 @@ Pin the auth flow to a specific [proxy](/proxies/overview) so logins, health che

How stable the exit IP is depends on the proxy type:

- **[ISP](/proxies/isp)** and **[datacenter](/proxies/datacenter)** proxies provide a stable exit IP within a single session, but Kernel does not guarantee the same IP across sessions. Sites with adaptive auth that trigger a step-up challenge (one-time code, device verification) when the client IP changes may flag the IP shift between the initial login and a subsequent health check or reauth.
- **[ISP](/proxies/isp)** proxies provide a static exit IP that persists across sessions, so the initial login, health checks, and reauths all exit through the same IP. The IP only changes in rare ISP-initiated replacement events or a temporary [failover to a backup endpoint](/proxies/isp#backup-endpoint-failover).
- **[Datacenter](/proxies/datacenter)** proxies assign a new exit IP per request. Sites with adaptive auth that trigger a step-up challenge (one-time code, device verification) when the client IP changes may flag these IP shifts.
- **[Residential](/proxies/residential)** proxies rotate IPs per connection — use them when you need legitimacy from a real ISP pool but can tolerate IP changes.
- **[Custom (BYO)](/proxies/custom)** proxies route through whatever you point them at, so this is the right pick if you need a truly static IP that persists across the initial login and every subsequent health check and reauth (e.g. an allowlisted egress your security team owns).
- **[Custom (BYO)](/proxies/custom)** proxies route through whatever you point them at, so pick one if the static IP must be infrastructure you control (e.g. an allowlisted egress your security team owns).

Create a proxy first, then attach it to the connection:

Expand Down
4 changes: 2 additions & 2 deletions browsers/bot-detection/overview.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -94,9 +94,9 @@ IP address is one of the strongest signals bot detection systems use. Kernel off

### ISP proxies

[ISP proxies](/proxies/isp) route traffic through data centers using IP addresses assigned by real internet service providers. They offer datacenter-level speed with better legitimacy than pure datacenter proxies, and every connection in a session exits through the same static IP — making them ideal for login flows and session-based workflows.
[ISP proxies](/proxies/isp) route traffic through data centers using IP addresses assigned by real internet service providers. They offer datacenter-level speed with better legitimacy than pure datacenter proxies, and every session attached to the proxy exits through the same static IP — making them ideal for login flows and session-based workflows.

Kernel's [stealth mode](/browsers/bot-detection/stealth) uses static ISP proxies that are hosted in data centers but announced on residential ISP networks, so they tend to appear residential by ASN to most of the internet. This matters for IP-reputation-based detection systems: a static IP on a residential ASN looks like a normal ISP customer, which generally achieves better pass rates than rotating residential IPs.
Kernel's [stealth mode](/browsers/bot-detection/stealth) uses ISP proxies from a shared pool that are hosted in data centers but announced on residential ISP networks, so they tend to appear residential by ASN to most of the internet. This matters for IP-reputation-based detection systems: a static IP on a residential ASN looks like a normal ISP customer, which generally achieves better pass rates than rotating residential IPs.

### Residential proxies

Expand Down
4 changes: 2 additions & 2 deletions browsers/bot-detection/stealth.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,7 @@ All Kernel browsers ship with anti-detection optimizations by default — you do

Enabling `stealth` mode adds two managed services on top:

1. **Default proxy** — traffic routes through a static [ISP proxy](/proxies/isp), providing a stable exit IP for the session.
1. **Default proxy** — traffic routes through an ISP proxy from a shared Kernel pool, providing a stable exit IP for the session.
2. **Automatic CAPTCHA solver** — solves [reCAPTCHAs](https://www.google.com/recaptcha/api2/demo), Cloudflare challenges, and similar tests automatically.

Both are opt-out so you can [bring your own](#bring-your-own-proxy-or-captcha-solver) where it makes sense.
Expand All @@ -17,7 +17,7 @@ Both are opt-out so you can [bring your own](#bring-your-own-proxy-or-captcha-so

### IP Rotation Behavior

The default stealth proxy provides a **static exit IP** — all connections within the session exit through the same IP address. If you override the default with a [residential proxy](/proxies/residential), exit IPs may change between connections. See [Residential routing and IP behavior](/proxies/residential#routing-and-ip-behavior) for details.
The default stealth proxy provides a **static exit IP for the session** — all connections within the session exit through the same IP address. A new session may exit through a different IP from the shared pool. If you need the same IP across sessions, [create an ISP proxy](/proxies/isp) and attach it with `proxy_id`. If you override the default with a [residential proxy](/proxies/residential), exit IPs may change between connections. See [Residential routing and IP behavior](/proxies/residential#routing-and-ip-behavior) for details.

To turn on stealth mode, set its flag when instantiating Kernel browsers:

Expand Down
4 changes: 4 additions & 0 deletions proxies/isp.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -10,6 +10,10 @@ ISP proxies provide a **static exit IP that persists across sessions** — every

This makes ISP proxies suitable for use cases that require a stable IP, such as IP allowlists or [managed auth](/auth/managed-auth) health checks. For comparison with other proxy types, see [IP rotation behavior across proxy types](/proxies/overview).

### Backup endpoint failover

For some organizations, Kernel attaches a backup ISP endpoint from a different provider to each ISP proxy. If the primary endpoint refuses connections, traffic temporarily exits through the backup endpoint's IP and returns to the primary IP once it's reachable again. If you allowlist the proxy's IP, sites might see the backup IP during a primary outage.

## Configuration

Create an ISP proxy with an exit IP in Singapore:
Expand Down
2 changes: 1 addition & 1 deletion proxies/overview.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -21,7 +21,7 @@ Kernel-provided proxies are unmetered and not billed, subject to the fair use ru
</Note>

<Info>
ISP proxies provide a **static exit IP that persists across sessions** — every browser session attached to the proxy exits through the same IP, and it only changes in rare ISP-initiated replacement events. This makes them suitable for IP allowlists or [managed auth](/auth/managed-auth) health checks that must egress from a single IP.
ISP proxies provide a **static exit IP that persists across sessions** — every browser session attached to the proxy exits through the same IP, and it only changes in rare ISP-initiated replacement events or a temporary [failover to a backup endpoint](/proxies/isp#backup-endpoint-failover). This makes them suitable for IP allowlists or [managed auth](/auth/managed-auth) health checks that must egress from a single IP.

Datacenter proxies use **rotating exit IPs** — a new exit IP is assigned per request, so different requests within the same browser session can exit through different IPs. For a stable IP across requests and sessions, use an ISP proxy or a [custom (BYO) proxy](/proxies/custom) pointed at infrastructure you control.

Expand Down
Loading