Burrowbox Docs

VPN locations

Pick a VPN type and a country, and a machine's browser and apps go online from there. Use it to see sites the way local users do, reach geo-restricted services, or get past bot checks.

Type What it does HTTPS
proxy Browse from a real IP in that country Passes through untouched
unlock Same, and also gets past bot checks and CAPTCHAs (Cloudflare "Just a moment…", etc.) Re-encrypted by the provider, so it can see the traffic (see below)

#Pricing

Both types are an add-on to the machine's normal rate:

Proxy Unlock
While the machine runs with the VPN on +$0.03 / hour +$0.06 / hour
Traffic $10.00 / GB $15.00 / GB
Connections — $3.00 per 1,000

Live values are in GET /api/vpn/locations (types[].pricing) and GET /api/pricing (vpn). Usage shows in your billing history as "running + VPN proxy/unlock" and "VPN … data".

#List types and locations

GET /api/vpn/locations needs no authentication.

{
  "available": true,
  "types": [
    { "type": "proxy", "name": "Proxy", "available": true, "description": "…", "pricing": { "centsPerHour": 3, "centsPerGb": 1000, "centsPer1kConnections": 0 } },
    { "type": "unlock", "name": "Unlock", "available": true, "description": "…", "pricing": { "centsPerHour": 6, "centsPerGb": 1500, "centsPer1kConnections": 300 } }
  ],
  "locations": [ { "country": "us", "name": "United States" }, { "country": "gb", "name": "United Kingdom" } ],
  "note": "Any two-letter country code works; these are the common ones. City targeting (e.g. newyork) is best effort."
}

#Turn it on

When creating a machine:

curl -X POST https://burrowbox.dev/api/machines \
  -H "Authorization: Bearer $BURROWBOX_KEY" -H "Content-Type: application/json" \
  -d '{"name": "acme", "vpn": {"type": "proxy", "country": "de"}}'

On an existing machine (live if it's running):

curl -X PUT https://burrowbox.dev/api/machines/2f6aeedcd3/vpn \
  -H "Authorization: Bearer $BURROWBOX_KEY" -H "Content-Type: application/json" \
  -d '{"vpn": {"type": "unlock", "country": "gb"}}'

Claiming from a warm pool takes the same vpn field, and it's applied to the ready machine instantly.

#Check where a machine browses from

GET /api/machines/{id}/vpn

{ "vpn": { "type": "proxy", "country": "de" }, "egress": { "ok": true, "ip": "91.108.196.68", "country": "DE", "city": "Berlin", "org": "AS209372 WS Telecom Inc" } }

Agents on the machine can ask the same with the machine MCP tool network_info.

#From an agent

Platform MCP tools: vpn_locations, machine_set_vpn, machine_vpn_status, plus a vpn argument on machine_create and pool_claim.

#HTTPS and privacy

unlock works by opening HTTPS traffic and re-encrypting it with the provider's (Bright Data's) certificate. While a machine uses unlock:

proxy leaves HTTPS end-to-end encrypted between the machine and the site.

#Notes