Bot developers
Two APIs. One string format.
The account API hands your bot its balance, usage, orders and ready-made proxy lines on a read-only key. The partner API creates customers, funds them and rotates their credentials. Every string follows one fixed token order, so your parser never has to guess.
Proof
Lines your bot can use. One GET.
/proxies builds ready-to-use lines from the credentials the account already holds — nothing is created, no data is spent. Ask for the country, the session model, the count (up to 1,000) and the format your bot parses.
Read the API docs# 3 sticky US lines in URL format — the key stays in an env var curl "https://api.basilproxies.com/api/v1/proxies?product=residential&country=us&session=sticky&count=3&format=url" \ -H "Authorization: Bearer $BASIL_API_KEY"
What the string looks like.
Build one by hand to see the token order, then let /proxies or the dashboard generate the rest. The port picks rotating or sticky; the password never carries anything.
eu-residential2.basilproxies.com:4243:basil_demo-country-de-city-berlin-session-k4mz61pq-lifetime-60:vq20hxw8Example with placeholder credentials — yours generate in the dashboard. Port 4242 rotates, 4243 holds one IP; targeting rides the username.
Strings
Every token, in its place.
The first line uses all five slots. Drop any of them and the rest keep their order — a parser that splits on hyphens after the username reads every string the pool will ever hand out.
Read the docs# Fixed order: country → city|asn → os → session → lifetime eu-residential2.basilproxies.com:4243:USER-country-de-city-berlin-type-residential-os-android-session-9f2k41ab-lifetime-60:PASS # URL format, rotating: same tokens, port 4242 http://USER-country-de:[email protected]:4242
Which product
Selling proxies with the bot? That's the partner API.
The account API is read-only by design — a leaked key exposes data, not money. When your bot needs to hand each customer their own credentials, the partner API does it in one call: POST /customers with an initial balance creates the customer, funds them from your pool and returns working credentials. Top up the same customer for repeat purchases, send an Idempotency-Key on every write, and take back whatever they leave unused.
See white-labelBefore you ask.
The account API (/api/v1) reads your own account: balance, usage, orders, subscriptions, proxy lines, sub-accounts. Seven GETs, nothing that spends money. The partner API (/api/reseller/v1) creates and funds customers from a wholesale pool — that's for bots that sell proxies, and it comes with a partner account.
60 requests a minute per account, shared by both of its keys; past that you get 429 with a Retry-After header. Two active keys at most; revoke one and it fails on the next request. Data is always in MB, 1 GB = 1000 MB.
New credentials can answer 407 for the first minute or two while the gateways pick them up. Retry before touching anything. If it persists, check that every targeting token sits on the username — the password carries nothing.
Yes, and it's the same result. Tokens ride the username, hyphen-separated, in a fixed order: country → city or ASN → OS → session → lifetime. The port picks the session model (4242 rotating, 4243 sticky) and the password never changes. When a hand-built string misbehaves, diff it against one from the dashboard.
Sub-accounts: up to five under one login, each with its own credentials and balance, listed by GET /res2/subaccounts. Meter each instance on its own sub-account and move gigabytes between them from the dashboard.
No. Poll /balance or /usage from a script — 60 a minute is plenty for a top-up check — or let the Discord bot's /alerts DM you at a threshold you set.