Download
- JSON: the full dataset, one record per provider with a products array. Supports
ETag/If-None-Match. - CSV: one row per provider × product, ready for spreadsheets.
- JSON Schema for a provider record, and the OpenAPI spec for the whole API.
- Markdown per provider, e.g. /providers/bright-data.md; everything at once in llms-full.txt.
Query it
# cheapest residential providers with SOCKS5 and crypto payment
curl "https://workingproxysites.info/api/v1/providers?type=residential&protocol=SOCKS5&payment=crypto&sort=price"
# side-by-side comparison
curl "https://workingproxysites.info/api/v1/compare?slugs=bright-data,oxylabs,decodo"
# what changed since yesterday (prices, products, new listings)
curl "https://workingproxysites.info/api/v1/changes?since=2026-09-25T00:00:00Z"AI agents can use the same data through the MCP server (search_providers, compare_providers, get_provider, list_changes). See For Agents and llms.txt.
What's in a record
- Products: one per proxy type sold (residential, mobile, datacenter, ISP), with pricing model, cheapest unit price in USD, minimum spend, advertised pool size, countries, targeting depth, protocols and session options.
- Terms: free trial, refund window, KYC requirements, payment methods, API access, other products, and IP-sourcing claims.
- Company: legal entity, founding year, headquarters, former names.
- Signals: community score (votes), live status from monitoring agents, and any red flags found.
- Provenance: source URLs, confidence (high, medium or low), the date it was checked, and a data version.
How it's built
- Providers are discovered from review coverage, segment searches and new-entrant searches, then screened.
- A researcher reads each provider's homepage, pricing, docs, terms and imprint, and searches for seizures, botnet reports, lawsuits and scams.
- An independent fact-checker re-opens the live sites, corrects the record, and blanks anything it can't confirm.
- A quality pass puts every price in one unit per pricing model (per GB, per IP per month, per port per month) so providers compare like for like, and checks each reported concern against its sources. Leaving a provider out takes a majority of three independent reviewers.
- Every change is logged. Prices are the providers' own advertised figures, not our measurements, so confirm them before buying.
We leave out providers that are defunct, seized, or credibly tied to botnets or attack infrastructure. Reported concerns that don't meet that bar are shown on the provider's page. Spotted an error? Post in Site Feedback.
Not listed, and why
- NetNut seized — On 2 Jul 2026 the FBI, with IRS-CI, Google, Lumen and Shadowserver, seized netnut.io in an action against the Popa botnet (2M+ devices) that populated NetNut's residential proxy network; the site showed an FBI seizure page when checked on 2026-09-26. Sources: krebsonsecurity.com, proxyway.com, theregister.com
- Asocks excluded — On 28-29 May 2026 Dutch police and the NCSC dismantled Asocks' infrastructure (about 200 servers). The service routed customer traffic through at least 17 million compromised devices enrolled via the PROXYLIB code in LumiApps; the investigation is ongoing. Sources: techtimes.com, proxyway.com
- PyProxy excluded — Google GTIG (29 Jan 2026) named pyproxy.com as a brand controlled by IPIDEA, whose SDKs it tied to the BadBox 2.0, Aisuru and Kimwolf botnets, and took legal action against the domains marketing IPIDEA brands. pyproxy.com was registered anew on 7 Aug 2026; the operator now named (HONGKONG LINGYUN NETWORK MDT INFOTECH LIMITED) claims a handover from the original team, which could not be verified. Sources: cloud.google.com, proxyway.com, proxyway.com, krebsonsecurity.com, rdap.verisign.com, pyproxy.com
- PlainProxies excluded — KrebsOnSecurity (8 Jan 2026): the Kimwolf botnet installed the ByteConnect SDK, distributed by PlainProxies, on infected devices; Synthient saw credential stuffing through it and said the SDK stayed active after PlainProxies ignored outreach. CEO Friedrich Kraft lists himself as a ByteConnect co-founder. Cloudflare named 3xK Tech GmbH, PlainProxies' operator, the top HTTP DDoS source (Jul 2025). Sources: krebsonsecurity.com, plainproxies.com, docs.plainproxies.com, blog.cloudflare.com, proxyway.com, plainproxies.com
- FineProxy excluded — Qurium Media Foundation reports (2018-2023) traced DDoS attacks on independent media, including Azerbaijani outlets (2018-2020) and Rappler (Oct 2023), to FineProxy infrastructure and documented falsified IP geolocation in RIPE records. FineProxy disputed the findings; per Qurium, its CEO offered to name the attacker if Qurium removed its articles. It did not answer CPJ's questions (Jul 2024). Sources: rappler.com, qurium.org, qurium.org, qurium.org, qurium.org, cpj.org
- Shifter excluded — KrebsOnSecurity (28 Jul 2022) reported that Microleaves, now Shifter, long got proxies from affiliates paid to spread its software, including by secretly bundling it with other programs, and tied its first admin account to a persona who posted about building a botnet in 2011. Kaspersky flagged the software as a trojan. Proxyway (updated Feb 2026) says Shifter's current IP sourcing is undisclosed. Sources: krebsonsecurity.com, proxyway.com, malwarebytes.com
- ProxyJet seized — proxyjet.io shows an FBI seizure notice (checked 2026-09-26): the FBI seized the domain with the DOJ and IRS-CI in a law-enforcement action against the NetNut residential proxy platform. Sources: proxyjet.io, proxyway.com, krebsonsecurity.com, krebsonsecurity.com
- LunaProxy defunct — Google Threat Intelligence Group (29 Jan 2026) named LunaProxy among the brands controlled by the operators of IPIDEA, whose SDKs it tied to the BadBox 2.0, Aisuru and Kimwolf botnets. lunaproxy.com no longer resolves (checked 2026-09-26). Sources: cloud.google.com, proxyway.com, proxyway.com, proxyway.com
- 922 Proxy defunct — Google Threat Intelligence Group (29 Jan 2026) named 922 Proxy among the brands controlled by the operators of IPIDEA, whose SDKs it tied to the BadBox 2.0, Aisuru and Kimwolf botnets. 922proxy.com no longer resolves (checked 2026-09-26). Sources: cloud.google.com, krebsonsecurity.com, krebsonsecurity.com, proxyway.com
- ABCProxy defunct — Google Threat Intelligence Group (29 Jan 2026) named ABC Proxy among the brands controlled by the operators of IPIDEA, whose SDKs it tied to the BadBox 2.0, Aisuru and Kimwolf botnets. abcproxy.com is sinkholed and unreachable (checked 2026-09-26). Sources: cloud.google.com, proxyway.com, rdap.verisign.com, web.archive.org