Development Proxy¶
403 Errors¶
The PSI development instance (https://discovery.development.psi.ch) is accessible only from restricted networks. Connecting from a disallowed IP address returns a 403 error.

To resolve this, connect through an allowed system. For operators, the recommended approach is to configure a SOCKS5 proxy.
Intended audience¶
This guide is for operators testing the Ingestor against the development SciCat instance at https://discovery.development.psi.ch.
Prerequisites¶
You need SSH access to an allowed server, usually the Ingestor server, which PSI should already have whitelisted.
Start the proxy¶
SSH from the command line¶
If you can connect to the Ingestor with SSH, start a SOCKS5 proxy with the -D option:
ssh -D 9999 ingestor.example.com
Alternatively, configure it in ~/.ssh/config so it starts automatically when you
connect to the Ingestor:
Host ingestor.example.com
DynamicForward 9999
PuTTY (Windows)¶
When using PuTTY, add D9999 in Connection → SSH → Tunnels. See the PuTTY documentation.
Enable the proxy in your browser¶
Configure your browser to use the SOCKS5 proxy. The recommended option is the FoxyProxy extension, available for Firefox, Chrome, and Edge.
After installing the extension, add a proxy with these values:
| Setting | Value |
|---|---|
| Title | OpenEM |
| Type | SOCKS5 |
| Hostname | localhost |
| Port | 9999 |
Enable the proxy after adding it. The FoxyProxy menu-bar icon should be coloured to match the OpenEM proxy entry.
Testing¶
Open https://discovery.development.psi.ch. A successful connection confirms that the proxy is active.