Connecting your apps

Once a port is open, point any tool that supports a proxy at it. This page shows the proxy address format and ready-to-use examples for browsers, curl, and code.

The proxy address

Each open port is a standard proxy on your local machine. Use the host where BlankTrail Proxy runs (127.0.0.1 for a local install) and the port number from the dashboard. A port is either SOCKS5 or HTTP, as chosen when you opened it.

socks5://127.0.0.1:20134
http://127.0.0.1:20250
TipThe Overview tab has a one-click copy button on each port that copies the full proxy address for you.

There is nowhere to enter the port in an application that cannot use a proxy at all. Interception exists for that case: the chosen programs' traffic is diverted to the port by the system, and the profile applies to them just the same — see Dashboard → System traffic interception.

Trust the certificate

For HTTPS to work without errors, the device or tool must trust the BlankTrail Proxy root certificate (see Installation → Root certificate). Some HTTP clients let you point at the certificate file directly instead of installing it system-wide.

Browsers & anti-detect browsers

Set the port as the browser's HTTP/SOCKS proxy (or, in an anti-detect browser, as the upstream proxy for a profile). For driving a real browser, open the port with the Browser preset so its fingerprint is matched and normalized.

It works as a drop-in local proxy for ZennoPoster, BAS, Puppeteer, Playwright, Selenium and any tool that supports an HTTP/HTTPS or SOCKS5 proxy — no code changes to your scripts.

curl

curl -x socks5://127.0.0.1:20134 https://example.com
curl -x http://127.0.0.1:20250 https://example.com

Code examples

Python (requests)

import requests

proxies = {
    "http": "socks5://127.0.0.1:20134",
    "https": "socks5://127.0.0.1:20134",
}
r = requests.get("https://example.com", proxies=proxies)
print(r.status_code)

Node.js (undici)

import { ProxyAgent, request } from 'undici'

const agent = new ProxyAgent('http://127.0.0.1:20250')
const { statusCode } = await request('https://example.com', { dispatcher: agent })
console.log(statusCode)

Telegram (MTProto)

A Telegram client cannot go through an ordinary fingerprint-spoofing proxy — it speaks its own protocol. For it you open a port with the MTProto protocol: from the outside it looks like an ordinary Telegram proxy, and the camouflage makes the connection resemble TLS to an unrelated site.

  1. In the open-port dialog choose the “MTProto” preset, or the mtproto protocol.
  2. Turn on the “Advanced” toggle in the dialog header — without it the MTProto section stays hidden. Leave the secret empty so the application generates a new one, or enter your own in the canonical ee… form.
  3. Open the port. The response carries a ready tg://proxy?server=…&port=…&secret=… link — that is what you open on the device with Telegram.
Open an MTProto port
curl -X POST -H "X-API-Key: YOUR_API_KEY" -H "Content-Type: application/json" \
  -d '{"port":20443,"protocol":"mtproto",
       "mtproto_camouflage_domain":"www.google.com"}' \
  http://127.0.0.1:8891/api/v1/ports/open
Response
{
  "port": 20443,
  "protocol": "mtproto",
  "status": "opened",
  "tg_link": "tg://proxy?server=203.0.113.10&port=20443&secret=ee…",
  "mtproto_secret": "ee…"
}
  • The camouflage domain is also the SNI the client presents: www.google.com by default. From the network's side the connection looks like an ordinary visit to that site.
  • A prober or a client with a wrong secret is by default spliced to the REAL camouflage site rather than cut off: a cut would itself reveal that a proxy is here.
  • If the UPSTREAM egress is itself an MTProto proxy, the faketls egress mode makes the port talk to it over fake TLS; auto chooses by itself, obfuscated is the ordinary obfuscation.
  • An MTProto port is not an HTTP proxy: it cannot be given to a browser or to curl, and TLS fingerprint spoofing does not apply to it.

n8n

n8n has a ready-made node: the n8n-nodes-blanktrail package installs from npm under Settings → Community nodes. The node opens a port, picks the browser profile and the route, and hands the proxy address to the next step of the workflow — with no HTTP code of your own and no hand-written API calls.

TipWhen BlankTrail and n8n both run in containers, put them on the same Docker network and address the proxy by container name rather than 127.0.0.1 — inside the n8n container that address points at the container itself.

Common connection issues

  • Certificate errors on HTTPS — the certificate isn't trusted on this device. Install it (Installation → Root certificate).
  • Connection refused — the port isn't open, or you used the wrong host/port. Check the Overview tab.
  • Wrong protocol — a SOCKS5 port won't accept HTTP-proxy settings and vice versa. Match the protocol shown on the port.
  • Proxy authentication refused — the ports demand a login and password, and the address carries none. Write the address in full: socks5://user:password@127.0.0.1:20134. In the recommended Docker run command the password is set by default.
  • The port was there and vanished — a port with no traffic closes itself after 30 minutes, counted from the moment it was opened. Give the port its own time (PUT /api/v1/port/{port}/idle with {"seconds": 0}) or list it in portmanager.startup_ports.
  • Everything works but the site recognises the client — check whether TLS pass-through is on for that port: with it the fingerprint of your own application goes out, not the chosen profile.