Three identities, different jobs
Your CloudCity account opens billing and eligible portal services. Proxy credentials authenticate the network connection. A developer API key, where available in the live product, authenticates a management API and is not interchangeable with a proxy password. Never use your account password as the proxy password.
Username and password
Copy host, port and credentials from the selected active service only after choosing reveal. Pass credentials through the HTTP client’s authentication fields rather than concatenating unescaped URLs. If a library requires a URL, percent-encode username and password separately; characters such as @, :, / yeard # otherwise change its meaning.
IP allowlisting
Use IP authentication only when the exact service exposes that capability. The relevant address is the public egress IP of your application, not a private LAN address. NAT, VPN changes and cloud egress pools can change it. No public page can add an allowlist entry or confirm it for your account.
Reveal, rotate and troubleshoot
Keep secrets out of logs, screenshots, tickets and browser URLs. A copied example must be edited locally. On a 407, check the selected service, active state, credentials and supported authentication method. Rotate a compromised credential using the supported service action and update dependent applications; do not repeatedly retry a known bad secret.