# PayPal Proxies: 1 Static IP for Payflow

> PayPal proxies for developers: Payflow Pro allowlists 16 server IPs and answers the rest with RESULT=1. A static ISP IP gives your app one address to register.

[Home](https://quanticdata.io/)/[Blog](https://quanticdata.io/blog/)/PayPal Proxies: 1 Static IP for Payflow

# PayPal Proxies: 1 Static IP for Payflow

Use casesSep 28, 2026·9 min read·By [Aldo Morese](https://quanticdata.io/about/), founder of QuanticData

How a cloud application reaches PayPal Payflow through a static egress IP: PayPal Manager accepts up to 16 Internet-facing server addresses, a changing cloud address gets RESULT=1 User authentication failed, and one dedicated ISP IP stays registered; paypal.com itself returns 1,693 words over plain HTTP on 28 September 2026

On this page [Two search terms, one of which is not about you](/blog/paypal-proxies/#two-search-terms-one-of-which-is-not-about-you) [Only Payflow Pro allowlists your IP, and it takes 16 of them](/blog/paypal-proxies/#only-payflow-pro-allowlists-your-ip-and-it-takes-16-of-them) [Why a cloud application cannot hold a slot](/blog/paypal-proxies/#why-a-cloud-application-cannot-hold-a-slot) [Which proxy network fits an allowlist](/blog/paypal-proxies/#which-proxy-network-fits-an-allowlist) [paypal.com itself needs no browser and no country](/blog/paypal-proxies/#paypal-com-itself-needs-no-browser-and-no-country) [The setting that works on PayPal](/blog/paypal-proxies/#the-setting-that-works-on-paypal)

PayPal proxies are a developer problem, not a scraping one. PayPal's Payflow Pro lets a merchant allowlist up to 16 Internet-facing server IPs in PayPal Manager and answers every other source with RESULT=1, User authentication failed. An application on cloud infrastructure whose outbound address changes on every deploy cannot hold one of those 16 slots; a dedicated static ISP IP can. That is the setting: an [ISP proxy](https://quanticdata.io/isp-proxies/) at $2.50/IP a month at volume, one address, registered once. We also read paypal.com itself on 28 September 2026: 1,693 words over plain HTTP, identical from the US and Germany, so nothing here needs a browser either.

## Two search terms, one of which is not about you

Type PayPal proxies into Google from the US and autocomplete offers residential proxies PayPal, buy proxies PayPal and PayPal proxy service. Those are people who want to pay a proxy vendor with PayPal. The Reddit thread on the SERP is a consumer asking whether a residential IP will stop PayPal asking for verification. Neither is this article, and we say so once: this page is about your server's outbound address to PayPal's APIs, not about PayPal accounts, and no proxy is a way around account or fraud controls.

The developer term is where the demand is precise. PayPal API static IP autocompletes to PayPal API IP addresses, IP address list and IP ranges; PayPal IP whitelist to PayPal whitelist and Payflow API. The first page for it is led by two PayPal help articles, the Braintree IP page on developer.paypal.com and a static-egress vendor's post on Payflow RESULT=1. There is no AI Overview and no People Also Ask. We fetched every one of the PayPal pages and built the answer from them.

## Only Payflow Pro allowlists your IP, and it takes 16 of them

PayPal's help article on allowlisting a server's IP address states the scope in one sentence: merchants are not required to allowlist specific IP addresses to access Classic or REST APIs, but PayPal offers optional IP address allowlisting for Payflow Pro via PayPal Manager. The REST API at api.paypal.com and the NVP/SOAP API at api-3t.paypal.com authenticate on credentials alone. Payflow Pro, the direct-processing gateway at payflowpro.paypal.com, adds the address check.

The feature lives at Account Administration, then Allowed IP Addresses (For API Transaction Processing), in PayPal Manager. The article gives its rules:

- Enter up to **16** server IP addresses, then Update.

- An asterisk represents a range.

- Each address must be Internet-facing.

- Only admin users can modify the list; other users can view it.

- Access from every IP address outside the list is blocked.

Once the list exists, the failure mode is documented in the Payflow transaction-responses reference. RESULT=1 with RESPMSG User authentication failed is returned for wrong credentials, invalid processor information, a test account hitting the live host, and, in PayPal's own words, the Allowed IP Address security feature being implemented and the transaction coming from an unknown IP address. Same code for four causes. Check USER, VENDOR, PARTNER and PWD first, then the host, then the address the gateway saw.

## Why a cloud application cannot hold a slot

The allowlist assumes your server has an address. A serverless function, a container on a shared cluster, an autoscaling group or a platform with a NAT pool does not have one in the sense PayPal Manager means: the egress address changes on deploy, on scale, on restart, and the range the platform publishes is far wider than 16 entries. Every change is a new RESULT=1 until someone logs into PayPal Manager as an admin and edits the list. That is the outage pattern the vendor post on the SERP is written around, and it is real.

The fix is to give the application one outbound identity that does not move. Route only the HTTP client that talks to payflowpro.paypal.com through a proxy with a fixed, dedicated IP, register that IP once, and leave the rest of the application's traffic on its normal path. Your code still connects to PayPal's hostname; the proxy supplies the source address the gateway checks.

```
import os, requests

# One static ISP IP, registered once in PayPal Manager.
proxy = os.environ["PAYFLOW_EGRESS_PROXY"]   # http://user:pass@isp-host:port

payflow = requests.post(
    "https://payflowpro.paypal.com",
    data=payflow_payload,
    proxies={"https": proxy},
    timeout=30,
)
```

Use the pilot host, pilot-payflowpro.paypal.com, with the same proxy before you touch production; the allowlist applies there too. And do not put the credentials in a browser, a log line or a repository; the proxy URL is a secret in the same class as PWD.

## Which proxy network fits an allowlist

An allowlist wants an address that is dedicated, static and reputable, in that order. Rotating residential exits fail the first two by design: the address changes per request or per session, which is the opposite of what PayPal Manager stores. A datacenter IP is static but shared reputation on a payment gateway is a risk you do not need to carry.

A static ISP IP is a dedicated address assigned by a real ISP and hosted in a datacenter: one IP, yours alone, unchanged for the life of the plan, with unlimited bandwidth on it. It is the network built for this shape of job, and it is why the pillar for this post is [ISP proxies](https://quanticdata.io/isp-proxies/) rather than residential. At volume the price is $2.50 per IP per month; on one to ten IPs it is $3.80. Payflow's list holds 16, so one IP per environment, pilot and live, leaves 14 slots for the rest of your infrastructure.

| Network | Address behaviour | Fits a 16-slot allowlist | Price from llms.txt |
| --- | --- | --- | --- |
| Static ISP | Dedicated, fixed, ISP-assigned | Yes: register once | $2.50/IP/month at volume |
| Residential, rotating | New IP per request or session | No: nothing to register | $0.80/GB |
| Datacenter | Static, shared ranges | Technically, with shared reputation | $0.50/GB |

Two allowlists are in play, and only one is yours. PayPal also publishes its own server ranges for merchants whose firewalls block outbound traffic: eight CIDR blocks, 64.4.240.0/21, 64.4.248.0/22, 66.211.168.0/22, 91.243.72.0/23, 173.0.80.0/20, 185.177.52.0/22, 192.160.215.0/24 and 198.54.216.0/23, covering live and sandbox. The same article recommends resolving the hostnames through DNS with default TTLs instead, and says an application that does allowlist must cycle through all the ranges until one answers. Braintree, PayPal's other gateway, publishes its production and sandbox IPs in a JSON file for the same reason. Register your egress with PayPal; resolve PayPal by name.

## paypal.com itself needs no browser and no country

The measurement side of this post is short because the answer is short. We audited paypal.com/us/home from a US residential exit and from a German one on 28 September 2026, with no cookies and no Accept-Language header.

| Fetch | Exit | Status | Bytes | Words | JSON-LD types |
| --- | --- | --- | --- | --- | --- |
| /us/home, plain HTTP | United States | 200 | 362,618 | 1,693 | 11 |
| /us/home, plain HTTP | Germany | 200 | not weighed | identical | 11 |
| robots.txt | United States | 200 | 2,628 | 1 sitemap | n/a |

The page is fully server-rendered: title, canonical, h1, 1,693 words and eleven JSON-LD types from Organization to MobileApplication, all in the first response. The German fetch returned the same title, the same canonical and the same word count, with no redirect to a /de/ page. PayPal does not localise the US home off the exit IP, so there is no number that changes with the country here, and no reason to render. If you are reading PayPal's public pages, developer docs or help centre for monitoring, `engine: tls` through [residential proxies](https://quanticdata.io/residential-proxies/) at $0.80/GB is the whole configuration: 362,618 bytes a page, 2,757 pages per gigabyte, $0.00029 each, counting a gigabyte as 10^9 bytes.

robots.txt is 2,628 bytes and closes what you would expect: checkout, sign-in injection, the /webscr/ and /cgibin/ legacy paths, the SDK and smart-button scripts, invoices, pay links and /cdn-cgi/. It names one sitemap index. None of it touches the help centre or the developer documentation we cite, which answered plain requests with their full text.

## The setting that works on PayPal

- **Network**: [ISP proxies](https://quanticdata.io/isp-proxies/), one dedicated static IP, $2.50/IP per month at volume ($3.80 on 1 to 10 IPs). That IP is the address you enter in PayPal Manager under Allowed IP Addresses (For API Transaction Processing), one of the 16 slots.

- **Fetch mode**: your own HTTP client, tunnelled through the ISP proxy for the Payflow calls only. For reading paypal.com pages, `engine: tls`: 1,693 words over plain HTTP, nothing behind JavaScript.

- **Country**: pick one exit country and keep it, because the allowlist stores an address, not a region; a US IP for a US merchant account is the obvious choice. The page content does not change with the exit, 1,693 words from the US and the same from Germany, so the country is an allowlist decision, not a content one.

- **When the proxy is not enough**: when your architecture needs more than 16 egress addresses, the allowlist itself is the limit and the answer is to consolidate egress behind fewer static IPs, not to add proxies. For REST and NVP/SOAP there is nothing to allowlist and the right proxy is none. For reading PayPal's public pages at scale, the [web scraping API](https://quanticdata.io/web-scraping-api/) fetches them over plain HTTP from $0.0002 a page.

- The free tier is real: every account gets $2 of free API usage per month, and the ISP IP is a flat monthly price with unlimited bandwidth on it. For what a static address does on other allowlists, see [how residential proxies can be legal](https://quanticdata.io/blog/how-can-residential-proxies-be-legal/) and [how to use a proxy with Python requests](https://quanticdata.io/blog/how-to-use-a-proxy-with-python-requests/).

### Sources & further reading

- [How do I allowlist my server’s IP address so it can access PayPal APIs? PayPal Help (TS1926)](https://www.paypal.com/us/cshelp/article/how-do-i-allowlist-my-server%E2%80%99s-ip-address-so-it-can-access-paypal-apis-ts1926)

- [What are the IP addresses for PayPal server endpoints? PayPal Help (TS1056)](https://www.paypal.com/us/cshelp/article/what-are-the-internet-protocol-ip-addresses-for-paypal-server-endpoints-ts1056)

- [Payflow transaction responses: RESULT values and RESPMSG text, PayPal Developer](https://developer.paypal.com/api/nvp-soap/payflow/integration-guide/transaction-responses/)

- [Braintree IP Addresses, PayPal Developer](https://developer.paypal.com/braintree/docs/reference/general/braintree-ip-addresses)

- [Get started with PayPal REST APIs, PayPal Developer](https://developer.paypal.com/api/rest/)

- [paypal.com/robots.txt (fetched 28 September 2026)](https://www.paypal.com/robots.txt)

## FAQ

Quick answers on paypal proxies.

[Something else? Ask us →](mailto:hello@quanticdata.io)

### Does PayPal require a static IP for its API?

Not for REST or Classic (NVP/SOAP). PayPal’s help centre states merchants are not required to allowlist server IP addresses for those APIs. Payflow Pro is the exception: PayPal Manager offers an optional Allowed IP Addresses list of up to 16 Internet-facing server addresses, and once it is enabled every other source is blocked.

### What does Payflow RESULT=1 mean?

User authentication failed, with four documented causes: wrong USER, VENDOR, PARTNER or PWD (all case-sensitive), invalid processor information, a test account submitting to the live host, or the Allowed IP Address feature seeing a transaction from an unknown IP address. Check the credentials and the host first; if both are right and the allowlist is on, the address Payflow saw is not one of the 16 entries.

### How many IP addresses can I allowlist in PayPal Manager?

Up to 16, under Account Administration and then Allowed IP Addresses (For API Transaction Processing). An asterisk stands for a range, each address must be Internet-facing, and only admin users can edit the list. One dedicated ISP IP per environment, pilot and live, uses 2 of the 16 slots.

### Which proxy type fits a PayPal Payflow allowlist?

A dedicated static ISP IP: one ISP-assigned address, yours alone, unchanged for the life of the plan, $2.50 per IP per month at volume or $3.80 on 1 to 10 IPs. Rotating residential exits change address per request or session, so there is nothing to register; a shared datacenter range is static but carries other tenants’ reputation onto a payment gateway.

### Should I hard-code PayPal’s IP ranges in my firewall?

PayPal recommends against it. Its help article lists 8 CIDR ranges for live and sandbox endpoints but says to resolve api.paypal.com, payflowpro.paypal.com and the other hostnames through DNS with default TTLs, and that an application which does allowlist must cycle through all the ranges until one responds. Register your egress IP with PayPal; resolve PayPal by name.

### Does paypal.com need a browser to read?

No. On 28 September 2026 paypal.com/us/home returned 200 OK, 362,618 bytes and 1,693 words to a plain HTTP client through a US residential exit, with 11 JSON-LD types in the response, and an identical page from a German exit with no redirect. For monitoring PayPal’s public, help or developer pages, engine: tls at $0.80/GB is the whole configuration, about $0.00029 a page.

## One address, registered once

A dedicated static ISP IP gives your Payflow integration a single egress address that survives every deploy, at a flat monthly price with unlimited bandwidth. For everything else PayPal serves over plain HTTP, every account gets $2 of free API usage per month.

[Start free — $2/month included](https://quanticdata.io/signup/)[Explore ISP Proxies from $2.50/IP](https://quanticdata.io/isp-proxies/)

## Related reading

[Use cases DoorDash Proxies: 485 Words, No Browser Needed DoorDash measured on 28 September 2026 through residential exits in the United States and Canada. The homepage answers a plain HTTP client with 200 OK and 485 words; a store page answers with 2.95 MB and 1,087 words of menu and prices, no JavaScript run. The browser is the one thing you should not buy here. When you want rows instead of pages, the DoorDash restaurants collector returned 50 restaurants for Austin, TX in 5.98 seconds. Read →](https://quanticdata.io/blog/doordash-proxies/) [Use cases Uber Eats Proxies: 99 Words Until You Render Uber Eats measured on 28 September 2026 through residential exits in the United States and the United Kingdom. The homepage answers a plain HTTP client with 200 OK and 99 words from the US, and redirects a UK exit to /gb with 42 words. Rendered in a browser it returns 206 words for 1,951,573 bytes. Nothing on the storefront exists until JavaScript runs and a delivery address is set, and Uber’s terms reserve commercial use of the data to parties with written permission. Read →](https://quanticdata.io/blog/ubereats-proxies/) [Use cases Zillow Proxies: 747 Words Over Plain HTTP Zillow measured on 28 September 2026 through residential exits in the United States and Germany. The homepage answers a plain HTTP client with 200 OK and 747 words from both countries; a listing page answers with 755,913 bytes and its price, beds, baths and square feet in the meta description, no JavaScript run. The browser is the one thing not to buy here. For rows, the Zillow search collector returned 20 listings for Austin, TX in 3.02 seconds and the Redfin collector 50 of 240 for one ZIP in 7.01. Read →](https://quanticdata.io/blog/zillow-proxies/)

## Also on this site

Quantic**Data**

Residential proxies & web data APIs for AI.

#### Proxies

- [Residential Basic](https://quanticdata.io/residential-proxies/#basic)

- [Residential Premium](https://quanticdata.io/residential-proxies/#plans)

- [Cheap Residential](https://quanticdata.io/cheap-residential-proxies/)

- [Mobile Proxies](https://quanticdata.io/mobile-proxies/)

- [Datacenter Proxies](https://quanticdata.io/datacenter-proxies/)

- [ISP Proxies](https://quanticdata.io/isp-proxies/)

- [Rotating Proxies](https://quanticdata.io/rotating-proxies/)

- [Sneaker Proxies](https://quanticdata.io/sneaker-proxies/)

- [SOCKS5 Proxies](https://quanticdata.io/socks5-proxies/)

- [IPv6 Proxies](https://quanticdata.io/ipv6-proxies/)

- [Proxy locations](https://quanticdata.io/proxies/)

#### Data APIs

- [MCP Server](https://quanticdata.io/mcp-server/)

- [Web Scraper API](https://quanticdata.io/web-scraping-api/)

- [SERP API](https://quanticdata.io/serp-api/)

- [Collectors](https://quanticdata.io/collectors/)

- [Web Data for AI](https://quanticdata.io/web-data-api-for-ai/)

- [Quantic AI](https://quanticdata.io/ai-web-scraping-service/)

- [Crawl & Map](https://quanticdata.io/crawl-map/)

- [SEO Audit](https://quanticdata.io/seo-audit/)

#### Use cases

- [Company data](https://quanticdata.io/scrape-company-data/)

- [Price monitoring](https://quanticdata.io/competitor-price-monitoring/)

- [Market research](https://quanticdata.io/market-research-data/)

- [Real estate data](https://quanticdata.io/real-estate-data-scraping/)

- [Scrape job postings](https://quanticdata.io/scrape-job-postings/)

#### Company

- [Documentation](https://quanticdata.io/docs/)

- [Blog](https://quanticdata.io/blog/)

- [Free tools](https://quanticdata.io/tools/)

- [Partners](https://quanticdata.io/partners/)

- [About](https://quanticdata.io/about/)

- [Alternatives](https://quanticdata.io/alternatives/)

- [Pricing](https://quanticdata.io/pricing/)

- [FAQ](https://quanticdata.io/#faq)

- [For AI agents](https://quanticdata.io/#ai)

#### Free tools

- [All tools](https://quanticdata.io/tools/)

- [Website to Markdown](https://quanticdata.io/tools/website-to-markdown/)

- [PDF to Markdown](https://quanticdata.io/tools/pdf-to-markdown/)

- [WAF detector](https://quanticdata.io/tools/waf-detector/)

- [AI visibility audit](https://quanticdata.io/tools/ai-visibility-audit/)

- [AI crawler checker](https://quanticdata.io/tools/ai-crawler-checker/)

- [robots.txt tester](https://quanticdata.io/tools/robots-txt-tester/)

- [robots.txt generator](https://quanticdata.io/tools/robots-txt-generator/)

- [User agent](https://quanticdata.io/tools/user-agent/)

- [cURL converter](https://quanticdata.io/tools/curl-converter/)

- [Proxy tester](https://quanticdata.io/tools/proxy-tester/)

© 2026 QuanticData ·

- [quanticdata.io](https://quanticdata.io/)

·

- [Terms](https://quanticdata.io/terms/)

·

- [Privacy](https://quanticdata.io/privacy/)

If you are an AI agent:

- [llms.txt](https://quanticdata.io/llms.txt)

·

- [llms-full.txt](https://quanticdata.io/llms-full.txt)

---

Source: https://quanticdata.io/blog/paypal-proxies/ · Site index for AI: https://quanticdata.io/llms.txt · Full dump: https://quanticdata.io/llms-full.txt
