Proxy Server

JoyProxy Server

Linux और Windows के लिए उच्च-प्रदर्शन HTTP / SOCKS5 proxy gateway। पाँच startup modes, वैकल्पिक external auth और traffic API।

Prebuilt Binaries

GitHub से prebuilt Linux और Windows binaries डाउनलोड करें। compilation की आवश्यकता नहीं।

Linux

Linux amd64 binary (v2.3) and optional CentOS 7 tarball from GitHub Releases.

Windows

joyproxy-gui.exe में desktop UI शामिल है; joyproxy.exe command-line gateway है।

Desktop Proxy Manager

joyproxy-gui.exe listen port, auth modes, start/stop controls और live logs के लिए visual interface प्रदान करता है — command line की आवश्यकता नहीं।

⚙️

Basic और Auth Settings

listen port, local IP, proxy type और open / whitelist / password modes एक जगह कॉन्फ़िगर करें।

▶️

One-Click Run Control

स्पष्ट running status feedback के साथ start, stop और config save करें।

📋

Built-in Log Viewer

अलग terminal खोले बिना real time में proxy activity देखें।

Command-Line Flags

सभी flags देखने के लिए ./joyproxy sps -h चलाएँ। सामान्य विकल्प:

Flagआवश्यकविवरण
-SनहींUpstream relay type: http या socks5 (default http)
-pहाँListen port(s), जैसे :8080 या :5001-5999
-gअनुशंसितइस सर्वर का public IP; auth API कॉल करते समय local_addr के रूप में उपयोग
-parentनहींDefault upstream URL यदि auth API upstream नहीं लौटाता
--auth-urlनहींExternal auth API URL (वैकल्पिक)
--auth-nouserनहींClients username/password नहीं भेजते; API प्रति connection decide करता है
--auth-cacheनहींAuth success cache TTL सेकंड में
--auth-fail-cacheनहींAuth failure cache TTL सेकंड में
--traffic-urlनहींExternal traffic reporting API URL (वैकल्पिक)
--daemonनहींबैकग्राउंड में चलाएँ (shell तुरंत लौटता है)
--foreverनहीं--daemon के साथ: crash पर worker auto-restart
--no-detachनहीं--daemon के साथ: attached रहें (systemd के साथ उपयोग करें)
--verboseनहींपूर्ण logs
--quietनहींकेवल errors
--max-conns-rateनहींप्रति सेकंड global max new connections (0 = unlimited)
--sniff-domainनहींHTTP CONNECT पर TLS SNI sniff करें
./joyproxy sps -h
./joyproxy sps -S http -p ":8080" -g "YOUR_PUBLIC_IP"

Server Capabilities

आपके infrastructure के लिए production-ready proxy gateway

🔀

Dual Protocol

कॉन्फ़िगर करने योग्य single port या port range पर HTTP और SOCKS5।

🔐

Flexible Auth

Open proxy, whitelist API, username/password, या full external auth API।

📊

Traffic API

connections समाप्त होने पर वैकल्पिक async traffic reporting।

⚡

Rate Limits

प्रति-उपयोगकर्ता connection limits, bandwidth caps और global connection rate limit।

🔄

Daemon Mode

production deployments के लिए auto-restart के साथ background mode।

🔍

TLS SNI Sniffing

HTTP CONNECT पर वैकल्पिक domain sniffing।

पाँच Authorization Modes

अपने deployment के अनुकूल mode चुनें

1. Open Proxy (no password)

कोई --auth-url नहीं। जो भी port तक पहुँच सके, credentials के बिना proxy उपयोग कर सकता है।

./joyproxy sps -S http -p ":8080" -g "YOUR_PUBLIC_IP"

2. Whitelist Authorization

--auth-nouser + --auth-url उपयोग करें। Clients password नहीं भेजते; आपका API प्रति connection allow/deny decide करता है (IP whitelist, target whitelist, आदि)।

./joyproxy sps -S http -p ":8080" -g "YOUR_PUBLIC_IP" \
  --auth-nouser --auth-url "https://your-api.example.com/auth"

3. Username / Password

--auth-nouser उपयोग न करें। Clients को Proxy-Authorization (HTTP) या SOCKS5 credentials भेजने होंगे। missing होने पर 407 लौटता है। --auth-url के बिना, credentials केवल locally check होते हैं (non-empty)।

./joyproxy sps -S http -p ":8080" -g "YOUR_PUBLIC_IP"

4. External Auth API

वैकल्पिक --auth-url प्रत्येक connection के लिए आपके endpoint पर HTTP GET भेजता है। --auth-nouser के साथ या बिना combine करें।

./joyproxy sps -S http -p ":8080" -g "YOUR_PUBLIC_IP" \
  --auth-url "https://your-api.example.com/auth"

5. External Traffic API

वैकल्पिक --traffic-url प्रत्येक connection समाप्त होने पर async HTTP GET भेजता है। आपका API 204 No Content लौटाना चाहिए। auth API के साथ combine किया जा सकता है।

./joyproxy sps -S http -p ":8080" -g "YOUR_PUBLIC_IP" \
  --auth-nouser --traffic-url "https://your-api.example.com/traffic"

External Auth API Reference

जब --auth-url set हो, joyproxy प्रत्येक connection के लिए इन query parameters के साथ HTTP GET भेजता है:

Parameterविवरण
userClient username (--auth-nouser होने पर empty)
passClient password
client_addrClient address IP:port
local_addrProxy listen address IP:port (-g + listen port से)
targetDestination: HTTP URL या SOCKS5 के लिए host:port
servicehttp या socks
spsहमेशा 1

आपका API 200 या 204 और header upstream: http://... या socks5://... के साथ allow के लिए respond करना चाहिए। deny के लिए upstream: ERR या non-200/204 लौटाएँ (client को 503, या X-Joyproxy-Reject-Status / X-Joyproxy-Deny के माध्यम से 407/429)।

Response Headerविवरण
upstreamइस connection के लिए upstream proxy URL
outgoingBind source IP hint
userconns / ipconnsMax concurrent connections (प्रति user)
userrate / iprateप्रति-connection bandwidth bytes/s (प्रति user)
userqps / ipqpsMax new connections प्रति सेकंड (प्रति user)

External Traffic API Reference

जब --traffic-url set हो, joyproxy प्रत्येक connection समाप्त होने पर async HTTP GET भेजता है। आपका API 204 No Content लौटाना चाहिए।

Parameterविवरण
acttraffic
bytesकुल bytes transferred (up + down)
client_addrClient IP:port
server_addrProxy service IP:port
target_addrTarget host या IP:port
usernameProxy auth username (यदि कोई)
upstreamउपयोग किया upstream URL (यदि कोई)
out_local_addrOutbound TCP local address
out_remote_addrOutbound TCP remote address
idhttp या socks
sniff_domainTLS SNI (केवल --sniff-domain enabled होने पर)

Daemon और systemd

production के लिए --daemon --forever उपयोग करें। systemd के साथ, --no-detach जोड़ें ताकि main process तुरंत exit न हो।

./joyproxy sps -S http -p ":5001-5999" -g "YOUR_PUBLIC_IP" \
  --auth-nouser --daemon --forever

# systemd unit: add --no-detach

Request Flow

Client joyproxy-server से connect करता है; traffic relay करने से पहले सर्वर वैकल्पिक रूप से आपका auth API कॉल करता है।

Version History

Recent releases. Full list on GitHub.

v2.3 (recommended)

  • SOCKS5 UDP via socks5:// upstream: relay datagrams through your parent proxy (same path as TCP).
  • Fix UDP upstream relay when parent returns 0.0.0.0 or loopback in UDP ASSOCIATE (use control TCP peer).
  • Includes v2.2: UDP ASSOCIATE reply uses -g public IP so remote clients can reach the relay port.

Auth API must return socks5:// (not http://) for service=socks / SOCKS5 UDP sessions.

v2.2

  • UDP ASSOCIATE BND address prefers -g public IP instead of local NIC IP.

v2.1

  • SOCKS5 UDP forwarding through socks5:// upstream on the same listen port.

अपने सर्वर पर Deploy करें

Binary डाउनलोड करें, startup mode कॉन्फ़िगर करें, और connections स्वीकार करना शुरू करें।

Binary डाउनलोड करें