Sell proxies from your own app — automatically.
Order every proxy, sub-user and CD key available in the GateProxy bot over a simple HTTPS JSON API. Orders are paid from your bot balance and delivered in seconds.
Get API access
API access is invite-only and approved manually to keep the platform safe.
/api.Authentication
Send your key in the Authorization header on every request.
Authorization: Bearer gpk_live_xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
- Keys start with
gpk_live_.X-API-Key: <key>is also accepted. - Never put the key in a URL — requests with
?api_key=or?token=are rejected withkey_in_url. - We only store a fingerprint of your key. If you lose it, generate a new one (the old one stops working instantly).
- Too many invalid keys from one IP automatically blocks that IP for 1 hour.
Quick start
Check your balance, list products, then buy a 1 GB plan.
# 1. who am I + balance curl https://api.gateproxy.store/v1/me \ -H "Authorization: Bearer $GATEPROXY_API_KEY" # 2. available products and your prices curl https://api.gateproxy.store/v1/products \ -H "Authorization: Bearer $GATEPROXY_API_KEY" # 3. place an order (Idempotency-Key makes retries safe) curl -X POST https://api.gateproxy.store/v1/orders \ -H "Authorization: Bearer $GATEPROXY_API_KEY" \ -H "Content-Type: application/json" \ -H "Idempotency-Key: order-1001" \ -d '{"product":"dataimpulse","plan":"1"}'
import os, uuid, requests API = "https://api.gateproxy.store/v1" S = requests.Session() S.headers["Authorization"] = f"Bearer {os.environ['GATEPROXY_API_KEY']}" print(S.get(f"{API}/me", timeout=20).json()) products = S.get(f"{API}/products", timeout=20).json()["products"] r = S.post(f"{API}/orders", json={"product": "dataimpulse", "plan": "1"}, headers={"Idempotency-Key": str(uuid.uuid4())}, timeout=120) data = r.json() if r.status_code == 201: print("delivered:", data["order"]["delivery"]) elif r.status_code == 202: print("processing / under review:", data["order"]["id"]) else: print("failed:", data["error"]["code"], data["error"]["message"])
const API = "https://api.gateproxy.store/v1"; const headers = { Authorization: `Bearer ${process.env.GATEPROXY_API_KEY}` }; const me = await (await fetch(`${API}/me`, { headers })).json(); console.log(me.balance_usd); const res = await fetch(`${API}/orders`, { method: "POST", headers: { ...headers, "Content-Type": "application/json", "Idempotency-Key": crypto.randomUUID() }, body: JSON.stringify({ product: "dataimpulse", plan: "1" }), }); const data = await res.json(); if (res.status === 201) console.log(data.order.delivery); else if (res.status === 202) console.log("poll", data.order.id); else console.error(data.error.code, data.error.message);
<?php $api = "https://api.gateproxy.store/v1"; $ch = curl_init("$api/orders"); curl_setopt_array($ch, [ CURLOPT_POST => true, CURLOPT_RETURNTRANSFER => true, CURLOPT_TIMEOUT => 120, CURLOPT_HTTPHEADER => [ "Authorization: Bearer " . getenv("GATEPROXY_API_KEY"), "Content-Type: application/json", "Idempotency-Key: " . bin2hex(random_bytes(12)), ], CURLOPT_POSTFIELDS => json_encode(["product" => "dataimpulse", "plan" => "1"]), ]); $body = json_decode(curl_exec($ch), true); $code = curl_getinfo($ch, CURLINFO_HTTP_CODE); if ($code === 201) print_r($body["order"]["delivery"]); else echo $body["error"]["code"] ?? "processing";
Conventions
| Topic | Rule |
|---|---|
| Base URL | https://api.gateproxy.store/v1 — HTTPS only. |
| Bodies | JSON, Content-Type: application/json, max 16 KB. |
| Money | All prices and balances are in USD (same balance as the bot). |
| Plans | A plan is the size in GB as a string: "1", "5", "0.12" (120 MB). |
| Times | ISO-8601 in UTC, e.g. 2026-10-02T08:15:00+00:00. |
| Request ID | Every response has an X-Request-Id header — include it when contacting support. |
| Errors | Non-2xx responses return {"error": {"code", "message", "request_id"}}. |
Order safety guarantees
You are never charged for an order you did not receive, and you never get a proxy you did not pay for.
The price was deducted and the credentials are in order.delivery.
Nothing was charged (or it was refunded instantly). error.code and error.message explain why.
The provider did not answer in time. Your payment is held while an admin verifies — you get the proxy or a full refund.
GET /v1/orders/{id} instead. A new key creates a second, separate order.Idempotency
Send a unique Idempotency-Key header (8–64 chars: letters, digits, _ - : .) with every POST /v1/orders. If your network drops and you retry with the same key, you receive the original order instead of buying twice ("idempotent_replay": true). Reusing a key with a different product/plan returns 409 idempotency_conflict.
Rate limits
| Limit | Default | Response when exceeded |
|---|---|---|
| Requests per API key | 60 / minute | 429 rate_limited + Retry-After |
| Orders per account | 10 / minute | 429 order_rate_limited |
| Orders processing at once | 3 | 429 too_many_inflight_orders |
| Requests per IP | 10 / second (burst 30) | 429 rate_limited |
| Daily spend (optional) | set by admin | 403 daily_limit_reached |
Each authenticated response includes X-RateLimit-Limit and X-RateLimit-Remaining. Need higher limits? Ask support — limits are set per account.
Endpoints
Health check
/v1/healthno auth{ "status": "ok", "time": "2026-10-02T08:15:00+00:00", "version": "1.0" }Account
/v1/meAPI key{
"user_id": 123456789,
"status": "approved",
"balance_usd": 25.4,
"pricing_tier": "standard",
"key": { "id": "key_4f1a9c2b7e01", "hint": "gpk_live_Ab3x…9QzK" },
"ip_whitelist": ["203.0.113.10"],
"limits": { "requests_per_minute": 60, "orders_per_minute": 10, "max_inflight_orders": 3, "daily_spend_limit_usd": null }
}Balance
/v1/balanceAPI key{ "balance_usd": 25.4, "currency": "USD" }List products
/v1/productsAPI keyReturns only products that are currently on sale, with your prices. CD-key products include live stock.
{
"products": [
{
"id": "dataimpulse", "name": "DataImpulse Proxy", "type": "subuser", "refundable": false,
"plans": [ { "plan": "1", "label": "1 GB", "price_usd": 1.1, "in_stock": true } ]
},
{
"id": "9proxy-cdkey", "name": "9 Proxy CD Key", "type": "cdkey", "refundable": false,
"plans": [ { "plan": "1", "label": "1 GB", "price_usd": 1, "in_stock": true, "stock": 14 } ]
}
]
}Get one product
/v1/products/{product_id}API keySame object as one item of the list above, under "product".
Create an order
/v1/ordersAPI key| Field | Type | Description |
|---|---|---|
product required | string | Product id from /v1/products, e.g. dataimpulse. |
plan required | string | Plan size in GB, e.g. "1". |
Idempotency-Key header | string | Strongly recommended. Makes retries safe. |
The request waits until the proxy is delivered (usually 2–15 s, up to 90 s). Use a client timeout of at least 120 seconds.
{
"order": {
"id": "ord_5c1f0b9a2e7d43a1b6c8d901",
"status": "completed",
"product": "dataimpulse", "plan": "1", "plan_label": "1 GB",
"price_usd": 1.1, "charged": true,
"created_at": "2026-10-02T08:15:02+00:00", "completed_at": "2026-10-02T08:15:06+00:00",
"delivery": {
"type": "subuser", "protocol": "HTTP/SOCKS5",
"server": "gw.dataimpulse.com", "port": 824,
"username": "a1b2c3d4_cr.ye", "password": "Xy7…", "subuser_id": "884512"
}
}
}{
"error": {
"code": "insufficient_balance",
"message": "Your balance is too low for this order. Nothing was charged.",
"balance_usd": 0.4, "price_usd": 1.1,
"order_id": "ord_…", "request_id": "req_9b2c4f1d0a6e7b38"
}
}{
"error": { "code": "provider_error", "message": "Traffic package unavailable", "refunded": true, "request_id": "req_…" },
"order": { "id": "ord_…", "status": "failed", "charged": false, … }
}List orders
/v1/orders?limit=20&status=completed&before=ord_…API keylimit 1–100 (default 20), optional status (processing, completed, failed, review, refunded), and before = the next_before value of the previous page.
{ "orders": [ { "id": "ord_…", "status": "completed", … } ], "next_before": "ord_…" }Get an order
/v1/orders/{order_id}API keyUse it to poll orders that returned 202. Completed orders always include the credentials again in delivery.
Products
Live availability and prices always come from GET /v1/products.
| Product id | Name | Type |
|---|---|---|
dataimpulse | DataImpulse Proxy | Sub-user |
9proxy | 9Proxy | Sub-user |
nodemaven | NodeMaven | Sub-user |
abc | ABC Proxy | Sub-user |
mesh | Mesh Proxy | Sub-user |
kafka | Kafka Proxy | Sub-user |
9proxy-cdkey | 9 Proxy CD Key | CD key |
rapid-cdkey | Rapid Proxy CD Key | CD key |
cli-cdkey | CLI Proxy CD Key | CD key |
rocket-cdkey | Rocket Proxy | CD key |
Delivery formats
{
"type": "subuser",
"protocol": "HTTP",
"server": "host.example",
"port": 1234,
"username": "…",
"password": "…",
"subuser_id": "…", // when available
"setup_guide": "https://…"
}{
"type": "cdkey",
"code": "XXXX-XXXX-XXXX",
"server": "host.example",
"port": 1234,
"setup_guide": "https://…"
}NodeMaven returns ports: {"http": …, "socks5": …} instead of a single port. Fields that do not apply are omitted.
Errors
| HTTP | code | Meaning · what to do |
|---|---|---|
| 400 | invalid_json invalid_request invalid_plan | Fix the request body. |
| 400 | key_in_url | Move the key to the Authorization header. |
| 401 | missing_api_key invalid_api_key | Check / regenerate your key in the bot. |
| 402 | insufficient_balance | Top up in the bot. Nothing was charged. |
| 403 | account_not_approved account_suspended | Contact support. |
| 403 | ip_not_allowed ip_blocked | Call from a whitelisted IP / contact support. |
| 403 | daily_limit_reached | Daily spend cap reached. |
| 404 | product_not_found plan_not_found order_not_found | Check ids against /v1/products. |
| 409 | out_of_stock product_unavailable | Try later or another product. Nothing was charged. |
| 409 | idempotency_conflict | Use a new key for a different order. |
| 429 | rate_limited order_rate_limited too_many_inflight_orders | Wait Retry-After seconds. |
| 502 | provider_error | Provider rejected the order — refunded, safe to retry with a new key. |
| 500 | internal_error | Retry later; share the request_id with support. |
| 202 | under_review / processing | Not an error: poll the order, do not re-order. |
Security best practices
Call the API from your backend. Never ship the key in a website, mobile app or browser extension.
Restrict the key to your server IPs in the bot — a leaked key is then useless elsewhere.
Regenerate the key in the bot if it may have leaked. The old key stops immediately.
Keep the key in environment variables or a secrets manager, never in git.
Full example — buy with safe retries
import os, time, uuid, requests API = "https://api.gateproxy.store/v1" HEAD = {"Authorization": f"Bearer {os.environ['GATEPROXY_API_KEY']}"} def buy(product, plan): idem = str(uuid.uuid4()) # one key per logical order, reused on retries for attempt in range(3): try: r = requests.post(f"{API}/orders", json={"product": product, "plan": plan}, headers={**HEAD, "Idempotency-Key": idem}, timeout=120) except requests.RequestException: time.sleep(2 ** attempt); continue # same idem key -> never double charged body = r.json() if r.status_code == 201: return body["order"]["delivery"] if r.status_code == 202: return wait_for(body["order"]["id"]) if r.status_code == 429: time.sleep(int(r.headers.get("Retry-After", "2"))); continue raise RuntimeError(f"{body['error']['code']}: {body['error']['message']}") def wait_for(order_id): while True: o = requests.get(f"{API}/orders/{order_id}", headers=HEAD, timeout=20).json()["order"] if o["status"] == "completed": return o["delivery"] if o["status"] in ("failed", "refunded"): raise RuntimeError(o["error"]["message"]) time.sleep(10) # "processing" or "review" print(buy("dataimpulse", "1"))
Support
Questions, higher limits or a stuck order? Message GateProxy support and include the X-Request-Id or order id. Machine-readable spec: openapi.json.