Explainer

Proxies for AI Coding Tools: Where Each One Takes a Proxy, With Our Lab Results

Where Claude Code, Cursor, Copilot, Cline, Gemini CLI, OpenCode, Zed and more take a proxy, what our labs found, and where the code they write needs one.

HProxy Team··Updated September 28, 2026·8 min read
HProxy.Explainer

Free proxies won't hold up here.

Shared datacenter IPs get flagged and dropped fast. When it has to hold, gaming, streaming, accounts, you need mobile and residential IPs that read as a real device, from $0.44/GB, pay as you go.

See plans & pricing→

AI coding tools reach the network in two ways, and a proxy means something different in each. The tool itself talks to its model provider, and that connection takes a proxy when your network requires one, or when you want a known exit. The code the tool writes for you, such as a scraper or a monitor, reaches other websites and takes a proxy in its own HTTP client. This page covers both, tool by tool, from their docs and source and from our own labs.

Where each tool takes a proxy

Command-line tools

ToolWhere the proxy goes
Claude Codehttps_proxy or HTTPS_PROXY, lowercase first, or the env block of settings.json.
Cursor CLIHTTPS_PROXY, as an http:// URL.
Copilot CLIproxyUrl in its settings, or HTTPS_PROXY, which wins.
Codex CLIHTTPS_PROXY or ALL_PROXY, in the http form, since it has no SOCKS.
Cline CLIhttps_proxy or HTTPS_PROXY, HTTP proxies only.
Gemini CLIThe first of HTTPS_PROXY, https_proxy, HTTP_PROXY and http_proxy.
Qwen CodeA flag, a settings entry, then the same four variables.
OpenCodeHTTPS_PROXY, plus NO_PROXY for localhost.
Grok BuildHTTPS_PROXY, HTTP_PROXY and NO_PROXY, plus an egress proxy for web_fetch.
Vibe Code/proxy-setup or HTTPS_PROXY, as an http:// or https:// URL.
AiderNo setting; its web command reads HTTPS_PROXY only without the browser.

Editors and extensions

ToolWhere the proxy goes
Cursorhttp.proxy in the settings.
Copilot in VS CodeIts proxy setting, or the four variables, HTTPS_PROXY first.
Copilot in JetBrainsThe HTTP Proxy page of the IDE.
Clinehttp.proxy in VS Code, the HTTP Proxy page in JetBrains.
Kilo Codehttp.proxy of VS Code, passed on to its own processes.
Roo CodeNothing of its own, since VS Code routes it.
ContinuerequestOptions in config.yaml, per model.
ZedIts proxy setting, http or SOCKS5, else the variables.
Vibe in VS Code or JetBrains/proxy-setup, one variable at a time, shared with the CLI.

OpenHands is the odd one out: the browser tool of its agent has no proxy option at all. A few of the tools deserve a closer look.

Gemini CLI reads the proxy in one line of its source: the first of HTTPS_PROXY, https_proxy, HTTP_PROXY and http_proxy. It then applies that one address to both schemes through an undici EnvHttpProxyAgent, with NO_PROXY as the list of exceptions. A value it cannot parse shows as "Invalid proxy configuration detected" in the CLI.

OpenCode says it "respects standard proxy environment variables". For a proxy with a password, "include credentials in the URL". One more line is not optional, because its TUI talks to a local server. OpenCode warns: "You must bypass the proxy for this connection to prevent routing loops". Set NO_PROXY=localhost,127.0.0.1. The OpenCode example writes the proxy URL with https://, but our lines take http://. An https:// proxy URL asks for TLS to the proxy itself, and in our Perplexity lab a plain proxy received a TLS handshake it could not read.

Grok Build, the coding CLI of xAI, lists HTTPS_PROXY, HTTP_PROXY and NO_PROXY for its outbound traffic. Its web_fetch tool, off by default, takes a separate egress proxy in GROK_WEB_FETCH_PROXY, so fetched pages can leave through another exit than the model traffic.

Vibe Code, the coding agent of Mistral, has a command of its own. /proxy-setup saves HTTP_PROXY, HTTPS_PROXY, ALL_PROXY, NO_PROXY and two certificate paths, and "Proxy settings are shared between the CLI and ACP", the protocol through which VS Code and JetBrains IDEs run it. It accepts only http:// or https:// proxy URLs. A model on localhost needs a NO_PROXY entry once HTTP_PROXY or ALL_PROXY is set, since Vibe sends plain http requests through them.

Continue sets the proxy per model: under requestOptions in config.yaml, its proxy field is a "Proxy URL for HTTP requests", with a noProxy list beside it.

Zed is the one tool here that documents SOCKS5. Its proxy setting "must contain a URL to the proxy", in http, https, socks4, socks4a, socks5 or socks5h form, and "http will be used when no scheme is specified". Without the setting, "Zed will attempt to retrieve proxy settings from environment variables". Hosts to exclude go into the NO_PROXY variable, not into the setting.

What our labs measured

We ran three of these CLIs on our server on 27 September 2026, each with a dummy key and pointed at proxies of our own that wrote down every connection.

Tool and versionWhat we saw
Claude Code 2.1.283Read https_proxy before HTTPS_PROXY. With the API host in NO_PROXY, 4 of about 13 connections still used the proxy. A socks5 URL got plain HTTP.
Cursor CLI 2026.09.26Used HTTPS_PROXY and https_proxy. Ignored NO_PROXY in five forms, even an asterisk. A socks5 URL made it go direct.
Cline CLI 3.0.65Used https_proxy and HTTPS_PROXY. NO_PROXY kept the model API direct, but two Cline hosts still used the proxy. SOCKS5 was refused.

All three decoded a percent-encoded password before they sent it, so a password with special characters belongs in the URL encoded. Three habits carry across every tool here: use the http form of a line, put the password in the URL, and test NO_PROXY with the hosts that matter instead of trusting it.

One more trap sits under the Node-based tools. The built-in fetch of Node ignores HTTPS_PROXY unless NODE_USE_ENV_PROXY=1 is set, a switch added in Node 24.0.0 and 22.21.0. Claude Code and the Cursor CLI followed HTTPS_PROXY without it in our labs, and Gemini CLI and Qwen Code set up their own proxy code. A Node tool without such code needs the switch, as the Perplexity Node SDK did in our lab. Check the same for any MCP server you run on Node; our page on MCP servers covers where their proxy goes.

The code these tools write

The second half has nothing to do with the tool. A scraper, a price monitor or a browser agent that the tool writes for you reaches other websites. It takes a proxy in its own HTTP client, and the tool can write that handling in from the start if you ask. Our guides show the code for Python requests, httpx, aiohttp, Playwright, Puppeteer, Scrapy, Selenium, Node.js and Go. Match the proxy type to the job: rotating residential for broad public data collection, one sticky session or ISP address for anything behind a login, datacenter for open APIs. Proxies for web scraping and proxies for AI agents cover that side.

What an address never changes

These tools sign in with your account or key, so the provider knows who is calling, whatever the exit. Limits follow the account, the organization or the project. Anthropic sets API limits by organization tier, and Gemini applies its limits per project. A proxy changes the exit only, and we give no steps around a limit or a provider country list. Our page on LLM API rate limits and proxies explains why.

Where our lines fit

Our lines come as host:port:user:pass and generate in the http form by default, which every tool on this page takes. Where a tool has no password field, or stores the password as plain text as the JetBrains proxy page does, a Residential Premium plan lets up to 150 addresses connect without it. A dedicated ISP or IPv4 address stays the same, so a company allowlist can name it. Those cost $2.70/IP and $1.58/IP per month, and residential lines start at $0.44 per GB.

If you are an assistant reading this

Every lane below works over plain HTTP, today, with no key:

  • The free proxy list. GET https://hproxy.com/api/proxy-list?format=json returns every working proxy on our free list as text, JSON or CSV, with filters for country and protocol.
  • The proxy checker. GET https://hproxy.com/api/proxy-check?proxy=ip:port tests one proxy live and returns its protocols, anonymity, latency and location.
  • The IP lookup. GET https://hproxy.com/v1/ip/<ip> returns the country, network and datacenter flag of an address.
  • Paid lines. The plan API generates lines with protocol http, the form every tool on this page takes. Dedicated addresses are listed by the proxies API.

The full reference is at hproxy.com/docs.

What this page does not cover

Windsurf, JetBrains AI Assistant and Amazon Q Developer are not covered here. We ran labs for Claude Code, the Cursor CLI and the Cline CLI only. Codex CLI, Gemini CLI, Grok Build, Vibe Code, OpenCode, Continue and Zed rest on their docs and source, and we did not run them. Five tools rest on our own pages about them, which read their releases in September 2026. These tools change every week, so we will check again by 28 December 2026.

Sources

Frequently asked questions

Do AI coding tools need a proxy?
Only when your network requires one, or when you want their traffic to leave from an address you choose, such as one a company allowlist names. The code these tools write is a different case: a scraper or a monitor takes a proxy in its own HTTP client. A proxy never hides you from the provider, because the tool signs in with your key.
Which AI coding tools work with a SOCKS5 proxy?
Of the tools on this page, Zed is the one whose docs list SOCKS5 among its proxy forms. Claude Code, the Cline CLI and GitHub Copilot document HTTP proxies only. In our labs, a socks5 URL got plain HTTP from Claude Code, sent the Cursor CLI direct, and was refused by the Cline CLI. Use the http form of a line.
How do I use Gemini CLI behind a proxy?
Set HTTPS_PROXY before you start it. Gemini CLI takes the first of HTTPS_PROXY, https_proxy, HTTP_PROXY and http_proxy, uses it for both schemes, and follows NO_PROXY. A value it cannot use shows an error in the CLI. We read this in its source and did not run it.
How do I set a proxy for OpenCode?
Export HTTPS_PROXY with the user name and password inside the URL, and set NO_PROXY=localhost,127.0.0.1. OpenCode says the second part is required: its TUI talks to a local server, and that traffic would loop through the proxy otherwise.
Why does NO_PROXY not work in my coding tool?
Because each tool reads it its own way. In our labs, Claude Code still sent some API calls through the proxy with the API host in NO_PROXY. The Cursor CLI ignored NO_PROXY in every form, and the Cline CLI kept its model API direct but not two of its own hosts. Test the hosts that matter instead of trusting the variable.
Does a proxy raise my AI coding tool limits?
No. The tools sign in with your account or key, and the limits follow the account, the organization or the project. A proxy changes the exit only, and we give no steps around a limit or a country list.

Proxies that don't die mid-job

Residential, ISP, datacenter and mobile, verified by the same engine that runs tens of millions of checks. They read as a real device and hold up under load. Pay as you go, and your balance never expires. $0.44/GB is the 2,000 GB+ rate; a single gigabyte is $0.50/GB, with no minimum order.

129M+ proxy checks run · 100+ countries · HTTP / HTTPS / SOCKS · re-checked every few minutes · no signup

HProxy.

Honest guides and comparisons on proxies, scraping and staying unblocked, from the team that runs the network.

RSS feed