Do these three things first

Confirm the exact protocol, host, and port from your provider; retype the username and password to remove hidden spaces; disable other proxy extensions and test again. If 407 remains, check whether the provider expects IP allowlisting instead of username/password authentication.

What 407 means

407 Proxy Authentication Required comes from the proxy server. It differs from 401 Unauthorized, which comes from a destination website. A repeated credential prompt usually means the proxy rejected credentials Chrome already supplied.

Check in this order

  1. Protocol: do not use a SOCKS5 endpoint as HTTP or infer the protocol from its port.
  2. Host: enter only a hostname or IP, without http://, a path, or a username.
  3. Port: confirm it is not a dashboard, API, or expired temporary port.
  4. Credentials: check case, trailing spaces, plan prefixes, and location parameters. Some providers encode region or session options in the username.
  5. Authorization: username/password may not work when the provider expects your public IP on an allowlist.
  6. Conflicts: only one extension can effectively control Chrome proxy settings. Temporarily disable other proxy, VPN, or policy extensions.

How ProxyFox handles credentials

ProxyFox supplies credentials only when the authentication challenge host and port strictly match the active profile. This prevents a password for one proxy from being sent to an unrelated server. Credentials remain in chrome.storage.local in the current Chrome profile and are not uploaded to a ProxyFox service.

Do not weaken browser security to fix a 407.Disabling TLS checks, ignoring certificate warnings, or sending one credential to every request will not correct proxy authentication.

A minimal isolation test

  1. Switch to Direct and verify that the base connection works.
  2. Create a clean profile containing only the host, port, and credentials; leave bypass rules empty.
  3. Use the provider's test endpoint or an HTTPS endpoint you trust.
  4. If a command-line request also fails, repeat the provider's documented curl example. When both fail, contact the proxy provider first.
  5. If command line works but Chrome fails, inspect enterprise policy at chrome://policy and disable competing proxy extensions.

Where to go next

If authentication succeeds but pages still fail, continue with Chrome proxy not working. If you are unsure whether to choose HTTP or SOCKS5, read HTTP vs HTTPS vs SOCKS5 vs VPN.