GateProxy developer API

Sell proxies from your own app — automatically.

Order every proxy, sub-user and CD key available in the GateProxy bot over a simple HTTPS JSON API. Orders are paid from your bot balance and delivered in seconds.

Base URL https://api.gateproxy.store/v1 Auth Bearer API key Format JSON Currency USD

Get API access

API access is invite-only and approved manually to keep the platform safe.

1Open the botStart @gateproxy_bot and send /api.
2Request accessTap Request API Access. An admin reviews it.
3Generate a keyAfter approval open 🔌 API → Generate API Key. It is shown once.
4Lock it to your IPRecommended: add your server IP under IP Whitelist.
💡
Orders are paid from your normal GateProxy balance. Top up in the bot with Deposit Money. Reseller accounts automatically get reseller prices through the API too.

Authentication

Send your key in the Authorization header on every request.

Header
Authorization: Bearer gpk_live_xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
  • Keys start with gpk_live_. X-API-Key: <key> is also accepted.
  • Never put the key in a URL — requests with ?api_key= or ?token= are rejected with key_in_url.
  • We only store a fingerprint of your key. If you lose it, generate a new one (the old one stops working instantly).
  • Too many invalid keys from one IP automatically blocks that IP for 1 hour.

Quick start

Check your balance, list products, then buy a 1 GB plan.

# 1. who am I + balance
curl https://api.gateproxy.store/v1/me \
  -H "Authorization: Bearer $GATEPROXY_API_KEY"

# 2. available products and your prices
curl https://api.gateproxy.store/v1/products \
  -H "Authorization: Bearer $GATEPROXY_API_KEY"

# 3. place an order (Idempotency-Key makes retries safe)
curl -X POST https://api.gateproxy.store/v1/orders \
  -H "Authorization: Bearer $GATEPROXY_API_KEY" \
  -H "Content-Type: application/json" \
  -H "Idempotency-Key: order-1001" \
  -d '{"product":"dataimpulse","plan":"1"}'

Conventions

TopicRule
Base URLhttps://api.gateproxy.store/v1 — HTTPS only.
BodiesJSON, Content-Type: application/json, max 16 KB.
MoneyAll prices and balances are in USD (same balance as the bot).
PlansA plan is the size in GB as a string: "1", "5", "0.12" (120 MB).
TimesISO-8601 in UTC, e.g. 2026-10-02T08:15:00+00:00.
Request IDEvery response has an X-Request-Id header — include it when contacting support.
ErrorsNon-2xx responses return {"error": {"code", "message", "request_id"}}.

Order safety guarantees

You are never charged for an order you did not receive, and you never get a proxy you did not pay for.

✓ Completed — 201

The price was deducted and the credentials are in order.delivery.

✕ Failed — 4xx / 502

Nothing was charged (or it was refunded instantly). error.code and error.message explain why.

⏳ Review — 202

The provider did not answer in time. Your payment is held while an admin verifies — you get the proxy or a full refund.

⚠️
Never retry a 202 with a new Idempotency-Key. Poll GET /v1/orders/{id} instead. A new key creates a second, separate order.

Idempotency

Send a unique Idempotency-Key header (8–64 chars: letters, digits, _ - : .) with every POST /v1/orders. If your network drops and you retry with the same key, you receive the original order instead of buying twice ("idempotent_replay": true). Reusing a key with a different product/plan returns 409 idempotency_conflict.

Rate limits

LimitDefaultResponse when exceeded
Requests per API key60 / minute429 rate_limited + Retry-After
Orders per account10 / minute429 order_rate_limited
Orders processing at once3429 too_many_inflight_orders
Requests per IP10 / second (burst 30)429 rate_limited
Daily spend (optional)set by admin403 daily_limit_reached

Each authenticated response includes X-RateLimit-Limit and X-RateLimit-Remaining. Need higher limits? Ask support — limits are set per account.

Endpoints

Health check

GET/v1/healthno auth
200 Response
{ "status": "ok", "time": "2026-10-02T08:15:00+00:00", "version": "1.0" }

Account

GET/v1/meAPI key
200 Response
{
  "user_id": 123456789,
  "status": "approved",
  "balance_usd": 25.4,
  "pricing_tier": "standard",
  "key": { "id": "key_4f1a9c2b7e01", "hint": "gpk_live_Ab3x…9QzK" },
  "ip_whitelist": ["203.0.113.10"],
  "limits": { "requests_per_minute": 60, "orders_per_minute": 10, "max_inflight_orders": 3, "daily_spend_limit_usd": null }
}

Balance

GET/v1/balanceAPI key
200 Response
{ "balance_usd": 25.4, "currency": "USD" }

List products

GET/v1/productsAPI key

Returns only products that are currently on sale, with your prices. CD-key products include live stock.

200 Response
{
  "products": [
    {
      "id": "dataimpulse", "name": "DataImpulse Proxy", "type": "subuser", "refundable": false,
      "plans": [ { "plan": "1", "label": "1 GB", "price_usd": 1.1, "in_stock": true } ]
    },
    {
      "id": "9proxy-cdkey", "name": "9 Proxy CD Key", "type": "cdkey", "refundable": false,
      "plans": [ { "plan": "1", "label": "1 GB", "price_usd": 1, "in_stock": true, "stock": 14 } ]
    }
  ]
}

Get one product

GET/v1/products/{product_id}API key

Same object as one item of the list above, under "product".

Create an order

POST/v1/ordersAPI key
FieldTypeDescription
product requiredstringProduct id from /v1/products, e.g. dataimpulse.
plan requiredstringPlan size in GB, e.g. "1".
Idempotency-Key headerstringStrongly recommended. Makes retries safe.

The request waits until the proxy is delivered (usually 2–15 s, up to 90 s). Use a client timeout of at least 120 seconds.

201 Created — delivered
{
  "order": {
    "id": "ord_5c1f0b9a2e7d43a1b6c8d901",
    "status": "completed",
    "product": "dataimpulse", "plan": "1", "plan_label": "1 GB",
    "price_usd": 1.1, "charged": true,
    "created_at": "2026-10-02T08:15:02+00:00", "completed_at": "2026-10-02T08:15:06+00:00",
    "delivery": {
      "type": "subuser", "protocol": "HTTP/SOCKS5",
      "server": "gw.dataimpulse.com", "port": 824,
      "username": "a1b2c3d4_cr.ye", "password": "Xy7…", "subuser_id": "884512"
    }
  }
}
402 — not enough balance (nothing charged)
{
  "error": {
    "code": "insufficient_balance",
    "message": "Your balance is too low for this order. Nothing was charged.",
    "balance_usd": 0.4, "price_usd": 1.1,
    "order_id": "ord_…", "request_id": "req_9b2c4f1d0a6e7b38"
  }
}
502 — provider rejected (refunded)
{
  "error": { "code": "provider_error", "message": "Traffic package unavailable", "refunded": true, "request_id": "req_…" },
  "order": { "id": "ord_…", "status": "failed", "charged": false, … }
}

List orders

GET/v1/orders?limit=20&status=completed&before=ord_…API key

limit 1–100 (default 20), optional status (processing, completed, failed, review, refunded), and before = the next_before value of the previous page.

200 Response
{ "orders": [ { "id": "ord_…", "status": "completed", … } ], "next_before": "ord_…" }

Get an order

GET/v1/orders/{order_id}API key

Use it to poll orders that returned 202. Completed orders always include the credentials again in delivery.

Products

Live availability and prices always come from GET /v1/products.

Product idNameType
dataimpulseDataImpulse ProxySub-user
9proxy9ProxySub-user
nodemavenNodeMavenSub-user
abcABC ProxySub-user
meshMesh ProxySub-user
kafkaKafka ProxySub-user
9proxy-cdkey9 Proxy CD KeyCD key
rapid-cdkeyRapid Proxy CD KeyCD key
cli-cdkeyCLI Proxy CD KeyCD key
rocket-cdkeyRocket ProxyCD key

Delivery formats

Sub-user type "subuser"
{
  "type": "subuser",
  "protocol": "HTTP",
  "server": "host.example",
  "port": 1234,
  "username": "…",
  "password": "…",
  "subuser_id": "…",   // when available
  "setup_guide": "https://…"
}
CD key type "cdkey"
{
  "type": "cdkey",
  "code": "XXXX-XXXX-XXXX",
  "server": "host.example",
  "port": 1234,
  "setup_guide": "https://…"
}

NodeMaven returns ports: {"http": …, "socks5": …} instead of a single port. Fields that do not apply are omitted.

Errors

HTTPcodeMeaning · what to do
400invalid_json invalid_request invalid_planFix the request body.
400key_in_urlMove the key to the Authorization header.
401missing_api_key invalid_api_keyCheck / regenerate your key in the bot.
402insufficient_balanceTop up in the bot. Nothing was charged.
403account_not_approved account_suspendedContact support.
403ip_not_allowed ip_blockedCall from a whitelisted IP / contact support.
403daily_limit_reachedDaily spend cap reached.
404product_not_found plan_not_found order_not_foundCheck ids against /v1/products.
409out_of_stock product_unavailableTry later or another product. Nothing was charged.
409idempotency_conflictUse a new key for a different order.
429rate_limited order_rate_limited too_many_inflight_ordersWait Retry-After seconds.
502provider_errorProvider rejected the order — refunded, safe to retry with a new key.
500internal_errorRetry later; share the request_id with support.
202under_review / processingNot an error: poll the order, do not re-order.

Security best practices

🔒 Server-side only

Call the API from your backend. Never ship the key in a website, mobile app or browser extension.

🌐 IP whitelist

Restrict the key to your server IPs in the bot — a leaked key is then useless elsewhere.

🔄 Rotate on doubt

Regenerate the key in the bot if it may have leaked. The old key stops immediately.

🗝 Store safely

Keep the key in environment variables or a secrets manager, never in git.

Full example — buy with safe retries

Python
import os, time, uuid, requests

API = "https://api.gateproxy.store/v1"
HEAD = {"Authorization": f"Bearer {os.environ['GATEPROXY_API_KEY']}"}

def buy(product, plan):
    idem = str(uuid.uuid4())               # one key per logical order, reused on retries
    for attempt in range(3):
        try:
            r = requests.post(f"{API}/orders", json={"product": product, "plan": plan},
                              headers={**HEAD, "Idempotency-Key": idem}, timeout=120)
        except requests.RequestException:
            time.sleep(2 ** attempt); continue    # same idem key -> never double charged
        body = r.json()
        if r.status_code == 201:
            return body["order"]["delivery"]
        if r.status_code == 202:
            return wait_for(body["order"]["id"])
        if r.status_code == 429:
            time.sleep(int(r.headers.get("Retry-After", "2"))); continue
        raise RuntimeError(f"{body['error']['code']}: {body['error']['message']}")

def wait_for(order_id):
    while True:
        o = requests.get(f"{API}/orders/{order_id}", headers=HEAD, timeout=20).json()["order"]
        if o["status"] == "completed": return o["delivery"]
        if o["status"] in ("failed", "refunded"): raise RuntimeError(o["error"]["message"])
        time.sleep(10)                     # "processing" or "review"

print(buy("dataimpulse", "1"))

Support

Questions, higher limits or a stuck order? Message GateProxy support and include the X-Request-Id or order id. Machine-readable spec: openapi.json.