Connecting your apps
Once a port is open, point any tool that supports a proxy at it. This page shows the proxy address format and ready-to-use examples for browsers, curl, and code.
The proxy address
Each open port is a standard proxy on your local machine. Use the host where BlankTrail Proxy runs (127.0.0.1 for a local install) and the port number from the dashboard. A port is either SOCKS5 or HTTP, as chosen when you opened it.
socks5://127.0.0.1:20134
http://127.0.0.1:20250
There is nowhere to enter the port in an application that cannot use a proxy at all. Interception exists for that case: the chosen programs' traffic is diverted to the port by the system, and the profile applies to them just the same — see Dashboard → System traffic interception.
Trust the certificate
For HTTPS to work without errors, the device or tool must trust the BlankTrail Proxy root certificate (see Installation → Root certificate). Some HTTP clients let you point at the certificate file directly instead of installing it system-wide.
Browsers & anti-detect browsers
Set the port as the browser's HTTP/SOCKS proxy (or, in an anti-detect browser, as the upstream proxy for a profile). For driving a real browser, open the port with the Browser preset so its fingerprint is matched and normalized.
It works as a drop-in local proxy for ZennoPoster, BAS, Puppeteer, Playwright, Selenium and any tool that supports an HTTP/HTTPS or SOCKS5 proxy — no code changes to your scripts.
curl
curl -x socks5://127.0.0.1:20134 https://example.com
curl -x http://127.0.0.1:20250 https://example.com
Code examples
Python (requests)
import requests
proxies = {
"http": "socks5://127.0.0.1:20134",
"https": "socks5://127.0.0.1:20134",
}
r = requests.get("https://example.com", proxies=proxies)
print(r.status_code)
Node.js (undici)
import { ProxyAgent, request } from 'undici'
const agent = new ProxyAgent('http://127.0.0.1:20250')
const { statusCode } = await request('https://example.com', { dispatcher: agent })
console.log(statusCode)
Telegram (MTProto)
A Telegram client cannot go through an ordinary fingerprint-spoofing proxy — it speaks its own protocol. For it you open a port with the MTProto protocol: from the outside it looks like an ordinary Telegram proxy, and the camouflage makes the connection resemble TLS to an unrelated site.
- In the open-port dialog choose the “MTProto” preset, or the mtproto protocol.
- Turn on the “Advanced” toggle in the dialog header — without it the MTProto section stays hidden. Leave the secret empty so the application generates a new one, or enter your own in the canonical ee… form.
- Open the port. The response carries a ready tg://proxy?server=…&port=…&secret=… link — that is what you open on the device with Telegram.
curl -X POST -H "X-API-Key: YOUR_API_KEY" -H "Content-Type: application/json" \
-d '{"port":20443,"protocol":"mtproto",
"mtproto_camouflage_domain":"www.google.com"}' \
http://127.0.0.1:8891/api/v1/ports/open
{
"port": 20443,
"protocol": "mtproto",
"status": "opened",
"tg_link": "tg://proxy?server=203.0.113.10&port=20443&secret=ee…",
"mtproto_secret": "ee…"
}
- The camouflage domain is also the SNI the client presents: www.google.com by default. From the network's side the connection looks like an ordinary visit to that site.
- A prober or a client with a wrong secret is by default spliced to the REAL camouflage site rather than cut off: a cut would itself reveal that a proxy is here.
- If the UPSTREAM egress is itself an MTProto proxy, the faketls egress mode makes the port talk to it over fake TLS; auto chooses by itself, obfuscated is the ordinary obfuscation.
- An MTProto port is not an HTTP proxy: it cannot be given to a browser or to curl, and TLS fingerprint spoofing does not apply to it.
n8n
n8n has a ready-made node: the n8n-nodes-blanktrail package installs from npm under Settings → Community nodes. The node opens a port, picks the browser profile and the route, and hands the proxy address to the next step of the workflow — with no HTTP code of your own and no hand-written API calls.
- n8n-nodes-blanktrail on npmInstalling via Community nodes, and the node's operations
- The node's source on GitHubHow the node works and what it calls in the API
Common connection issues
- Certificate errors on HTTPS — the certificate isn't trusted on this device. Install it (Installation → Root certificate).
- Connection refused — the port isn't open, or you used the wrong host/port. Check the Overview tab.
- Wrong protocol — a SOCKS5 port won't accept HTTP-proxy settings and vice versa. Match the protocol shown on the port.
- Proxy authentication refused — the ports demand a login and password, and the address carries none. Write the address in full: socks5://user:password@127.0.0.1:20134. In the recommended Docker run command the password is set by default.
- The port was there and vanished — a port with no traffic closes itself after 30 minutes, counted from the moment it was opened. Give the port its own time (PUT /api/v1/port/{port}/idle with {"seconds": 0}) or list it in portmanager.startup_ports.
- Everything works but the site recognises the client — check whether TLS pass-through is on for that port: with it the fingerprint of your own application goes out, not the chosen profile.