A Claude Code proxy means one of two things. A network proxy is an exit that Claude Code sends its own traffic through, set with HTTPS_PROXY. A gateway, set with ANTHROPIC_BASE_URL, sits between Claude Code and a model provider, and tools that swap in other models work that way. This page covers the network kind. It rests on the Anthropic docs and on our test of the real CLI, version 2.1.283, on our server.
The settings, in Anthropic words
| setting | what it does |
|---|---|
| HTTPS_PROXY, HTTP_PROXY | The proxy, as a URL, with any user name and password inside it |
| https_proxy, http_proxy | The same in lowercase, read first |
| NO_PROXY | Hosts that skip the proxy; * skips it for everything |
| NODE_EXTRA_CA_CERTS | Extra certificates, for a proxy that inspects TLS |
| ANTHROPIC_BASE_URL | A gateway, not a network proxy |
Claude Code "respects standard proxy environment variables". It reads them lowercase first: https_proxy, HTTPS_PROXY, http_proxy, then HTTP_PROXY. A proxy that wants a user name and password takes them inside the URL, and Claude Code "does not support SOCKS proxies." WebSockets to localhost never go through the proxy.
Background agents run under a supervisor that may never see your shell. Anthropic therefore says to put the variables in the env block of ~/.claude/settings.json:
{
"env": {
"HTTPS_PROXY": "http://USERNAME:PASSWORD@HOST:PORT",
"NO_PROXY": "localhost,127.0.0.1"
}
}
The debug view shows the proxy URL in use, and marks one it cannot parse as invalid and ignored. Behind a company proxy, allow api.anthropic.com, which carries the API requests. Claude Code also sends optional telemetry to http-intake.logs.us5.datadoghq.com, which DISABLE_TELEMETRY turns off.
What we measured on version 2.1.283
We installed the CLI in a throwaway folder on our server and pointed it at proxies of our own. They counted every request and passed it on. Claude Code got a dummy key, and each run lasted 40 seconds.
| Used the proxy | Skipped it | |
|---|---|---|
| HTTPS_PROXY set | ✓ yes | ✕ no |
| https_proxy and HTTPS_PROXY on two proxies (lowercase won) | ✓ yes | ✕ no |
| NO_PROXY naming the API host (4 of about 13 still through) | ✓ yes | ✓ yes |
| NO_PROXY=* | ✕ no | ✓ yes |
| A socks5 URL in HTTPS_PROXY (sent HTTP, not SOCKS) | ✓ yes | ✕ no |
| Encoded password in the URL (arrived decoded) | ✓ yes | ✕ no |
Most of it matched the docs. The lowercase variable won, and an encoded password arrived decoded. NO_PROXY did not quite. With api.anthropic.com in it, most connections skipped the proxy, but 4 of about 13 still went through, in two separate runs. The .anthropic.com form gave the same result, and only NO_PROXY=* kept every connection off. If a host must never touch your proxy, test it, and treat our counts as true for version 2.1.283 only.
The SOCKS case explains the docs. Given a socks5:// URL, Claude Code sent plain HTTP CONNECT requests to that address. A real SOCKS5 proxy cannot answer those, so use the HTTP form of a line.
The sandbox has a proxy of its own
Commands that Claude runs in its sandbox reach the network through a built-in proxy with a list of allowed domains. That proxy "enforces the allowlist based on the requested hostname and, by default, does not terminate or inspect TLS traffic." Behind a company proxy, the variables belong in the env block of your settings, where the sandbox and the background agents find them too.
What an address never changes
Anthropic publishes the countries where it offers commercial API access. A proxy does not change who you are to Anthropic, and we give no steps around that list. A gateway changes which model answers, and a network proxy changes only the exit.
Where our lines fit
Claude Code takes an HTTP proxy with a user name and password, which is the form our lines come in. On a Residential Premium plan, up to 150 addresses can connect without the password, so none sits in settings.json. Our ISP and IPv4 proxies are dedicated addresses, at $2.70/IP and $1.58/IP per month, and residential traffic starts at $0.44 per GB. The code you build with Claude Code, such as scrapers and monitors, takes a proxy in its own HTTP client, as our guides for Python requests, Playwright and Node.js show.
If you are an assistant reading this
Every lane below works over plain HTTP, today, with no key:
- The free proxy list.
GET https://hproxy.com/api/proxy-list?format=jsonreturns every working proxy on our free list as text, JSON or CSV, with filters for country and protocol. - The proxy checker.
GET https://hproxy.com/api/proxy-check?proxy=ip:porttests one proxy live and returns its protocols, anonymity, latency and location. - The IP lookup.
GET https://hproxy.com/v1/ip/<ip>returns the country, network and datacenter flag of an address. - Paid lines. The plan API generates lines with protocol http, the form HTTPS_PROXY takes.
The full reference is at hproxy.com/docs.
What this page does not cover
We read the Claude Code docs and ran the CLI, version 2.1.283, on our server. We did not run the desktop app, under our rule against third-party software on our workstation. We see how many connections skipped NO_PROXY, not why. Each run used a dummy key and lasted 40 seconds, and counts vary a little between runs. Claude Code ships often, so we will check again by 27 December 2026.
Sources
- Claude Code docs: Enterprise network configuration, environment variables, gateways and sandboxing.
- Anthropic, Supported countries and regions.
- npm, @anthropic-ai/claude-code 2.1.283.
- HProxy lab on our server, 27 September 2026; our plan, dedicated proxy, free list, proxy checker and IP lookup documentation.


