Proxy Server

JoyProxy Server

High-performance HTTP / SOCKS5 proxy gateway for Linux and Windows. Five startup modes, optional external auth and traffic APIs.

Prebuilt Binaries

Download prebuilt Linux and Windows binaries from GitHub. No compilation required.

Linux

Linux amd64 binary (v2.3) and optional CentOS 7 tarball from GitHub Releases.

Windows

joyproxy-gui.exe includes a desktop UI; joyproxy.exe is the command-line gateway.

Desktop Proxy Manager

joyproxy-gui.exe offers a visual interface for listen port, auth modes, start/stop controls, and live logs โ€” no command line required.

โš™๏ธ

Basic & Auth Settings

Configure listen port, local IP, proxy type, and open / whitelist / password modes in one place.

โ–ถ๏ธ

One-Click Run Control

Start, stop, and save config with clear running status feedback.

๐Ÿ“‹

Built-in Log Viewer

Watch proxy activity in real time without opening a separate terminal.

Command-Line Flags

Run ./joyproxy sps -h to show all flags. Common options:

FlagRequiredDescription
-SNoUpstream relay type: http or socks5 (default http)
-pYesListen port(s), e.g. :8080 or :5001-5999
-gRecommendedPublic IP of this server; used as local_addr when calling auth API
-parentNoDefault upstream URL if auth API does not return upstream
--auth-urlNoExternal auth API URL (optional)
--auth-nouserNoClients do not send username/password; API decides per connection
--auth-cacheNoAuth success cache TTL in seconds
--auth-fail-cacheNoAuth failure cache TTL in seconds
--traffic-urlNoExternal traffic reporting API URL (optional)
--daemonNoRun in background (shell returns immediately)
--foreverNoWith --daemon: auto-restart worker on crash
--no-detachNoWith --daemon: stay attached (use with systemd)
--verboseNoFull logs
--quietNoErrors only
--max-conns-rateNoGlobal max new connections per second (0 = unlimited)
--sniff-domainNoSniff TLS SNI on HTTP CONNECT
./joyproxy sps -h
./joyproxy sps -S http -p ":8080" -g "YOUR_PUBLIC_IP"

Server Capabilities

Production-ready proxy gateway for your infrastructure

๐Ÿ”€

Dual Protocol

HTTP and SOCKS5 on configurable single port or port range.

๐Ÿ”

Flexible Auth

Open proxy, whitelist API, username/password, or full external auth API.

๐Ÿ“Š

Traffic API

Optional async traffic reporting when connections end.

โšก

Rate Limits

Per-user connection limits, bandwidth caps, and global connection rate limit.

๐Ÿ”„

Daemon Mode

Background mode with auto-restart for production deployments.

๐Ÿ”

TLS SNI Sniffing

Optional domain sniffing on HTTP CONNECT.

Five Authorization Modes

Choose the mode that fits your deployment

1. Open Proxy (no password)

No --auth-url. Anyone who can reach the port may use the proxy without credentials.

./joyproxy sps -S http -p ":8080" -g "YOUR_PUBLIC_IP"

2. Whitelist Authorization

Use --auth-nouser + --auth-url. Clients send no password; your API decides allow/deny per connection (IP whitelist, target whitelist, etc.).

./joyproxy sps -S http -p ":8080" -g "YOUR_PUBLIC_IP" \
  --auth-nouser --auth-url "https://your-api.example.com/auth"

3. Username / Password

Do not use --auth-nouser. Clients must send Proxy-Authorization (HTTP) or SOCKS5 credentials. Returns 407 if missing. Without --auth-url, credentials are only checked locally (non-empty).

./joyproxy sps -S http -p ":8080" -g "YOUR_PUBLIC_IP"

4. External Auth API

Optional --auth-url sends an HTTP GET to your endpoint for each connection. Combine with or without --auth-nouser.

./joyproxy sps -S http -p ":8080" -g "YOUR_PUBLIC_IP" \
  --auth-url "https://your-api.example.com/auth"

5. External Traffic API

Optional --traffic-url sends an async HTTP GET when each connection ends. Your API should return 204 No Content. Can be combined with auth API.

./joyproxy sps -S http -p ":8080" -g "YOUR_PUBLIC_IP" \
  --auth-nouser --traffic-url "https://your-api.example.com/traffic"

External Auth API Reference

When --auth-url is set, joyproxy sends an HTTP GET for each connection with these query parameters:

ParameterDescription
userClient username (empty if --auth-nouser)
passClient password
client_addrClient address IP:port
local_addrProxy listen address IP:port (from -g + listen port)
targetDestination: HTTP URL or host:port for SOCKS5
servicehttp or socks
spsAlways 1

Your API should respond with 200 or 204 and header upstream: http://... or socks5://... to allow. Return upstream: ERR or non-200/204 to deny (client gets 503, or 407/429 via X-Joyproxy-Reject-Status / X-Joyproxy-Deny).

Response HeaderDescription
upstreamUpstream proxy URL for this connection
outgoingBind source IP hint
userconns / ipconnsMax concurrent connections (per user)
userrate / ipratePer-connection bandwidth bytes/s (per user)
userqps / ipqpsMax new connections per second (per user)

External Traffic API Reference

When --traffic-url is set, joyproxy sends an async HTTP GET when each connection ends. Your API should return 204 No Content.

ParameterDescription
acttraffic
bytesTotal bytes transferred (up + down)
client_addrClient IP:port
server_addrProxy service IP:port
target_addrTarget host or IP:port
usernameProxy auth username (if any)
upstreamUpstream URL used (if any)
out_local_addrOutbound TCP local address
out_remote_addrOutbound TCP remote address
idhttp or socks
sniff_domainTLS SNI (only when --sniff-domain enabled)

Daemon & systemd

Use --daemon --forever for production. With systemd, add --no-detach so the main process does not exit immediately.

./joyproxy sps -S http -p ":5001-5999" -g "YOUR_PUBLIC_IP" \
  --auth-nouser --daemon --forever

# systemd unit: add --no-detach

Request Flow

Client connects to joyproxy-server; server optionally calls your auth API before relaying traffic.

Version History

Recent releases. Full list on GitHub.

v2.3 (recommended)

  • SOCKS5 UDP via socks5:// upstream: relay datagrams through your parent proxy (same path as TCP).
  • Fix UDP upstream relay when parent returns 0.0.0.0 or loopback in UDP ASSOCIATE (use control TCP peer).
  • Includes v2.2: UDP ASSOCIATE reply uses -g public IP so remote clients can reach the relay port.

Auth API must return socks5:// (not http://) for service=socks / SOCKS5 UDP sessions.

v2.2

  • UDP ASSOCIATE BND address prefers -g public IP instead of local NIC IP.

v2.1

  • SOCKS5 UDP forwarding through socks5:// upstream on the same listen port.

Deploy on Your Server

Download the binary, configure your startup mode, and start accepting connections.

Download Binary