> ## Documentation Index
> Fetch the complete documentation index at: https://tbd-6fc993ce-hypeship-restricted-destination-routing-docs.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

# ISP Proxies

ISP (Internet Service Provider) proxies are hosted on datacenter infrastructure but use IP addresses assigned by real residential ISPs. Because the ASN belongs to a residential ISP, target sites see them as residential IPs — while the underlying datacenter hosting gives you the speed and stability you'd expect from a datacenter proxy.

## IP Rotation Behavior

ISP proxies provide a **static exit IP that persists across sessions** — every tab, request, reconnection, and future browser session attached to this proxy exits through the same IP. The IP only changes in rare ISP-initiated replacement events.

This makes ISP proxies suitable for use cases that require a stable IP, such as IP allowlists or [managed auth](/auth/managed-auth) health checks. For comparison with other proxy types, see [IP rotation behavior across proxy types](/proxies/overview).

## Configuration

Create an ISP proxy with an exit IP in Singapore:

<Info>
  ISP proxies support country targeting in the United States (`US`), Singapore (`SG`), the United Kingdom (`GB`), France (`FR`), and Germany (`DE`). If you omit `country`, the proxy defaults to `US`.
</Info>

<CodeGroup>
  ```typescript Typescript/Javascript theme={null}
  import Kernel from '@onkernel/sdk';

  const kernel = new Kernel();

  const proxy = await kernel.proxies.create({
    type: 'isp',
    name: 'my-sg-isp-proxy',
    config: {
      country: 'SG',
    },
  });

  const browser = await kernel.browsers.create({
    proxy_id: proxy.id,
  });
  ```

  ```python Python theme={null}
  from kernel import Kernel

  kernel = Kernel()

  proxy = kernel.proxies.create(
      type="isp",
      name="my-sg-isp-proxy",
      config={
          "country": "SG",
      },
  )

  browser = kernel.browsers.create(proxy_id=proxy.id)
  ```

  ```go Go theme={null}
  package main

  import (
  	"context"

  	"github.com/kernel/kernel-go-sdk"
  )

  func main() {
  	ctx := context.Background()
  	client := kernel.NewClient()

  	proxy, err := client.Proxies.New(ctx, kernel.ProxyNewParams{
  		Type: kernel.ProxyNewParamsTypeIsp,
  		Name: kernel.String("my-sg-isp-proxy"),
  		Config: kernel.ProxyNewParamsConfigUnion{
  			OfProxyNewsConfigIspProxyConfig: &kernel.ProxyNewParamsConfigIspProxyConfig{
  				Country: kernel.String("SG"),
  			},
  		},
  	})
  	if err != nil {
  		panic(err)
  	}

  	browser, err := client.Browsers.New(ctx, kernel.BrowserNewParams{
  		ProxyID: kernel.String(proxy.ID),
  	})
  	if err != nil {
  		panic(err)
  	}
  	_ = browser
  }
  ```
</CodeGroup>

## Configuration parameters

* **`country`** (optional) - ISO 3166 country code. Supported values are `US`, `SG`, `GB`, `FR`, and `DE`. Defaults to `US`.
* **`bypass_hosts`** (optional) - Array of hostnames that bypass the proxy and connect directly (max 100 entries)

## Restricted destinations

ISP proxies don't route restricted destinations automatically. Kernel attaches the provider that carries `.gov`, country government domains, and a set of banking, payment, and postal destinations to residential proxies only, so those requests from an ISP proxy fall back to the default provider, which carries some of them and returns a `502` on the rest.

If your workload targets them, use a [residential proxy](/proxies/residential#restricted-destination-routing) with no targeting, country-only targeting, US state targeting, or city targeting.

## Bypass hosts

Configure specific hostnames to bypass the proxy:

<CodeGroup>
  ```typescript Typescript/Javascript theme={null}
  import Kernel from '@onkernel/sdk';

  const kernel = new Kernel();

  const proxy = await kernel.proxies.create({
    type: 'isp',
    name: 'isp-with-bypass',
    bypass_hosts: [
      'localhost',
      'internal.service.local',
      '*.amazonaws.com',
    ],
  });
  ```

  ```python Python theme={null}
  from kernel import Kernel

  kernel = Kernel()

  proxy = kernel.proxies.create(
      type="isp",
      name="isp-with-bypass",
      bypass_hosts=[
          "localhost",
          "internal.service.local",
          "*.amazonaws.com",
      ]
  )
  ```

  ```go Go theme={null}
  package main

  import (
  	"context"

  	"github.com/kernel/kernel-go-sdk"
  )

  func main() {
  	ctx := context.Background()
  	client := kernel.NewClient()

  	proxy, err := client.Proxies.New(ctx, kernel.ProxyNewParams{
  		Type: kernel.ProxyNewParamsTypeIsp,
  		Name: kernel.String("isp-with-bypass"),
  		BypassHosts: []string{
  			"localhost",
  			"internal.service.local",
  			"*.amazonaws.com",
  		},
  	})
  	if err != nil {
  		panic(err)
  	}
  	_ = proxy
  }
  ```
</CodeGroup>

See the [overview](/proxies/overview#bypass-hosts) for full bypass host rules and examples.

## Getting the static IP address

Because an ISP proxy has a static exit IP, you can read that IP once and reuse it — for example, to add it to an IP allowlist. The IP is returned as `ip_address` in the response when you [create a proxy](https://kernel.sh/docs/api-reference/proxies/create-a-proxy) and when you [get a proxy by ID](https://kernel.sh/docs/api-reference/proxies/get-proxy-by-id).

<CodeGroup>
  ```typescript Typescript/Javascript theme={null}
  const proxy = await kernel.proxies.create({
    type: 'isp',
    name: 'my-isp-proxy',
  });

  console.log(proxy.ip_address);
  ```

  ```python Python theme={null}
  proxy = kernel.proxies.create(
      type="isp",
      name="my-isp-proxy",
  )

  print(proxy.ip_address)
  ```

  ```go Go theme={null}
  proxy, err := client.Proxies.New(ctx, kernel.ProxyNewParams{
  	Type: kernel.ProxyNewParamsTypeIsp,
  	Name: kernel.String("my-isp-proxy"),
  })
  if err != nil {
  	panic(err)
  }

  fmt.Println(proxy.IPAddress)
  ```
</CodeGroup>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.