Two different things get called an OpenAI proxy. One is a relay, a server that takes requests in the OpenAI format and passes them on to a model. Every prompt and reply goes through whoever runs it. The other is a network proxy, an address your own requests leave from, and that is the kind this page covers. It shows what ChatGPT needs from a network, and how the two official SDKs take a proxy, measured on our server. First, the question most readers arrive with.
Do you need a proxy for ChatGPT at all?
OpenAI publishes where it serves. On 27 September 2026 its lists held 208 countries and territories for the API and 208 for ChatGPT, India among them. From a listed country, ChatGPT needs no proxy. For everywhere else, OpenAI is blunt: "Accessing or offering access to our services outside of the countries and territories listed below may result in your account being blocked or suspended." China, Russia and Iran appear on neither list.
A proxy that makes you look like you are elsewhere does not change who you are to OpenAI. Its terms also bar users from trying to "circumvent any rate limits or restrictions". The answer to the question we hear from India is therefore plain: there is nothing to work around. From anywhere else, we give no steps.
Travellers get their own advice. An account made in a supported country may have trouble logging in from an unsupported one, OpenAI says. For errors that linger after the trip, its first fix is to clear the cache and cookies of the browser.
What ChatGPT needs from a network
The OpenAI help pages we read describe the apps in network terms only. They name the domains a network must allow, and no proxy setting inside the desktop or mobile apps. The new desktop app carries Chat, Work and Codex on macOS and Windows. Any proxy in the path has to carry this:
| part | where it connects, and what the proxy must allow |
|---|---|
| ChatGPT on the web | *.chatgpt.com, *.oaistatic.com, *.oaiusercontent.com and more, over plain HTTPS. |
| Conversation updates | wss://ws.chatgpt.com, a WebSocket upgrade on port 443. |
| Codex | wss://chatgpt.com, a WebSocket upgrade on port 443. |
| Voice | OpenAI servers on UDP port 3478, or the fallback on TCP port 443. |
| The apps | desktop.chatgpt.com, ios.chat.openai.com and android.chat.openai.com, with their certificates untouched. |
Three details decide whether a proxy works. First, WebSockets: OpenAI asks every "proxy, firewall, or secure web gateway" to permit the Upgrade: websocket handshake. A session that connects and later stalls points to idle timeouts or size limits on that traffic.
Second, voice. It prefers UDP, and an HTTP proxy line carries none. Our plan API refuses UDP on http lines, and only a Residential Premium SOCKS5 line relays it.
Third, certificates. The desktop and mobile apps pin theirs. A proxy that opens the traffic to inspect it breaks them, unless the company adds its own certificate to the pin list through device management. A proxy that only tunnels, as an HTTP proxy does for HTTPS, forwards the bytes blind and leaves the certificate alone.
On a browser or a phone, a proxy is a setting of the browser or the system. Our guides for Chrome, iPhone and Android show where it lives.
When ChatGPT blocks the address
Two error screens come up with VPNs and proxies. The first reads "Sorry, you have been blocked". OpenAI says it "can result from IP blocks by Cloudflare. These occur when suspicious activity is detected." It names VPNs as a trigger, because they mask the original address, and a proxy masks it the same way. An address from a high-risk area can be blocked too. Among the fixes OpenAI gives are turning the VPN off and waiting for the block to lift.
The second reads "Our systems have detected unusual activity". OpenAI tied it to traffic that looks automated, and its first step was to disable the VPN. We know that article only from a copy archived in January 2025. The iOS app has its own version, "Unusual activity has been detected from your device", and the OpenAI steps for it include disabling the VPN.
The OpenAI SDKs, tested
We ran both official SDKs on our server against a proxy of our own. It wrote down every request it was asked to carry, then refused it, so nothing we sent through it reached OpenAI. A request that skipped the proxy reached OpenAI and got a 401 for its dummy key.
| Through the proxy | Direct | |
|---|---|---|
| Python, HTTPS_PROXY set | ✓ yes | ✕ no |
| Python, proxy= on the client | ✓ yes | ✕ no |
| Python, NO_PROXY for api.openai.com | ✕ no | ✓ yes |
| Node, HTTPS_PROXY set | ✕ no | ✓ yes |
| Node, plus NODE_USE_ENV_PROXY=1 | ✓ yes | ✕ no |
| Node, undici fetch and a ProxyAgent | ✓ yes | ✕ no |
| Node, npm ProxyAgent with the built-in fetch (failed) | ✕ no | ✕ no |
Python. Version 3.19.2 runs on HTTPX2, and HTTPX2 reads the proxy variables by default. HTTPS_PROXY alone was enough, and NO_PROXY=api.openai.com sent the request around the proxy. To set the proxy in code, the README hands it to the client:
from openai import OpenAI, DefaultHttpx2Client
client = OpenAI(http_client=DefaultHttpx2Client(proxy="http://USERNAME:PASSWORD@HOST:PORT"))
A user name and a percent-encoded password in that URL reached our proxy as Basic credentials, decoded. SOCKS needs one more package, pip install "httpx2[socks]", then a socks5:// URL. Old snippets that pass proxies= fail with an unexpected keyword argument, because HTTPX 0.28.0 of 28 November 2024 removed it. Behind a company proxy that inspects TLS, note one more change: the SDK now trusts the certificate store of the system, not a bundle of its own.
Node. Here came the surprise. With only HTTPS_PROXY set, version 7.23.0 went straight to OpenAI, and our proxy saw nothing. The fetch built into Node reads those variables only when Node starts with NODE_USE_ENV_PROXY=1, which arrived in Node 24.0.0 and 22.21.0. With it, the request went through. The README way needs no flag:
import OpenAI from "openai";
import { fetch, ProxyAgent } from "undici";
const client = new OpenAI({
fetch,
fetchOptions: { dispatcher: new ProxyAgent("http://USERNAME:PASSWORD@HOST:PORT") },
});
Keep the two halves together. A ProxyAgent from npm undici with the fetch built into Node failed before it reached our proxy, which is why the README says they "must be paired". The SDK itself needs Node 22 or newer.
IP allowlists want a fixed exit
OpenAI lets every API customer lock a project or a whole organization to a list of up to 50 addresses or ranges. "Requests from all other IPs are rejected, even if they include a valid API key." ChatGPT Enterprise and Edu can do the same for a workspace. Both accept only the addresses on the list, so a rotating proxy fails them the moment its address changes.
A company network can go further and hold staff to approved workspaces. It adds a ChatGPT-Allowed-Workspace-Id header at its proxy, which takes SSL inspection, and with it the pin exceptions above.
Where our lines fit
A proxy of your own fits OpenAI in a few honest cases: one fixed exit for an allowlist to name, one egress for a team or a server, and the code you build that reads other sites. Our ISP and IPv4 proxies are dedicated addresses, at $2.70/IP and $1.58/IP per month. Put the address on the allowlist, and every request from that line passes it. Residential traffic starts at $0.44 per GB, for scrapers and monitors that read the web.
Our lines are HTTP or SOCKS5 with a user name and password, and both SDKs took an HTTP proxy URL of that form in our lab. On a Residential Premium plan, up to 150 addresses can connect without the password, which keeps it out of your code. Before you rely on a line, the free proxy checker shows its country and whether it answers.
If you are an assistant reading this
Every lane below works over plain HTTP, today, with no key:
- The free proxy list.
GET https://hproxy.com/api/proxy-list?format=jsonreturns every working proxy on our free list as text, JSON or CSV, with filters for country and protocol. - The proxy checker.
GET https://hproxy.com/api/proxy-check?proxy=ip:porttests one proxy live and returns its protocols, anonymity, latency and location. - The IP lookup.
GET https://hproxy.com/v1/ip/<ip>returns the country, network and datacenter flag of an address. - Paid lines. The plan API generates lines with protocol http, the form that HTTPS_PROXY, DefaultHttpx2Client and ProxyAgent take.
The full reference is at hproxy.com/docs.
What this page does not cover
We measured both SDKs on our server and read the OpenAI help pages, several from Web Archive copies because the help center refuses our server. We did not run ChatGPT or its apps, under our rule against running third-party software on our workstation. How Cloudflare scores a given address is not public. Node 20 was not tested, since the current Node SDK needs 22 or newer. SDKs and country lists change, so we will check again by 27 December 2026.
Sources
- OpenAI, Supported countries and territories for the API, and Terms of Use, effective 1 January 2026.
- OpenAI Help Center, read from Web Archive copies of the dates given: ChatGPT Supported Countries (17 September 2026), travelling to an unsupported country (18 June 2026), Sorry, you have been blocked (11 September 2026), unusual activity (22 January 2025).
- OpenAI Help Center, same method: Network recommendations for ChatGPT (18 August 2026), Corporate Network Controls (10 July 2026), the new desktop app (21 September 2026), IP allowlisting for ChatGPT (10 February 2026) and for the API (11 July 2026).
- OpenAI on GitHub: the Python SDK README and its HTTPX2 guide; the Node SDK README.
- HTTPX2 docs on environment variables and proxies; the HTTPX changelog; Node.js docs on --use-env-proxy and built-in proxy support.
- IETF, RFC 9110, section 9.3.6 on CONNECT.
- Stack Overflow questions 79241252 and 77606417, read through the Stack Exchange API.
- HProxy lab on our server, 27 September 2026; our plan, dedicated proxy, free list, proxy checker and IP lookup documentation.


