Skip to main content
Cloud & AI Hub
Browse
Glossary AI Directory Playgrounds Models Prompts Explainers Strategy Matrix Benchmark Decoder

Reverse Proxy

A server that sits in front of backend apps and forwards client requests to them.

Last reviewed: July 25, 2026

What is a reverse proxy?

A reverse proxy accepts incoming client connections and relays them to internal servers. Clients think they are talking to one host; the proxy handles routing to the correct backend.

Forward vs reverse proxy

TypeSits nearExample
Forward proxyClientCorporate HTTP proxy
Reverse proxyServerNGINX in front of app servers

Common capabilities

  • TLS termination — decrypt HTTPS at the proxy
  • Caching — store static responses
  • Compression — gzip/brotli responses
  • Security — hide internal topology, WAF rules
  • Routing — path-based rules to different services

NGINX, HAProxy, Envoy, Traefik, Caddy, and cloud-managed equivalents (Cloudflare, AWS ALB).

In modern stacks

Reverse proxies often sit between a load balancer and application pods. Service meshes extend this with sidecar proxies for mTLS and fine-grained traffic policies.

What people get wrong

  • Forgetting forwarding headers. Without X-Forwarded-For/X-Forwarded-Proto, backends see the proxy’s IP and think everything is HTTP — breaking logs, rate limits, and redirect logic.
  • Buffering surprises. Default response buffering breaks Server-Sent Events and streaming responses (a constant gotcha for LLM apps — see streaming); disable it on streaming routes.
  • Timeout mismatches. A 30-second proxy timeout in front of a 60-second backend produces mysterious 502/504s; align the chain, longest at the edge.

Reverse Proxy vs. Load Balancer vs. API Gateway

These three terms are often used interchangeably but describe overlapping rather than identical roles: a reverse proxy’s core function is sitting in front of one or more backend servers and forwarding client requests to them, hiding the backend’s existence from clients; a load balancer is a reverse proxy specifically focused on distributing traffic across multiple backend instances for scalability and redundancy; and an API gateway is a reverse proxy with additional API-specific concerns layered on top, like authentication, rate limiting, and request/response transformation. In practice, a single piece of software (NGINX, HAProxy, Envoy) is often configured to serve any of these roles depending on how it’s set up, which is why the terminology tends to blur together in casual usage even though the underlying use cases have distinct emphases.

A forward proxy, by contrast, sits in front of clients rather than servers, forwarding outbound requests on their behalf — the opposite direction of a reverse proxy, and a useful distinction to keep straight since the two terms are easy to confuse despite describing essentially mirror-image roles.

Advertisement (In-Content)

Historical figures and technical concepts for informational purposes only. Not technical, professional, legal, or financial advice. Sources: Official Documentation.