407: check proxy authentication
Status 407 indicates that proxy authentication is required or has not been accepted. Check the credentials, any spaces introduced by copying and pasting, the host, port and protocol. In curl, distinguish --proxy-user from --user. Do not put passwords in public logs while investigating.
401 and 403: identify who is responding
Status 401 generally indicates that authentication is required or invalid for the requested resource. A 403 means the request was understood but refused. Record the response and check whether it comes from the proxy or the target. Review your account permissions and the rules of the service before trying again.
429: slow down and respect the limit
Status 429 signals excessive request frequency. Follow Retry-After when present and reduce your rate. A limit may apply to an account, key, cookie or IP, so changing exits is not a universal fix. Set a maximum number of attempts and increase the delay between retries.
Timeouts: isolate the network path
First check the gateway hostname and port, then try an authorized diagnostic target. Set explicit timeouts. A timeout can originate in your connection, the proxy or the destination; one observation is not enough to conclude that the entire network is down.
Frequently asked questions
What should I send to support?
The UTC time, order reference, protocol, error code and reproduction steps, without a password. A redacted response example is more useful than a trace containing secrets.
Should I retry every error automatically?
No. Incorrect credentials or an authorization refusal need a correction. Transient errors can be retried with explicit delays and attempt limits.