A Cursor proxy means one of two things. One is a gateway, an OpenAI-compatible endpoint that puts other models behind Cursor, which is what searches such as "cursor deepseek proxy" are after. Cursor warns that custom gateways "can introduce additional latency, rate limiting, and compatibility issues." The other is a network proxy, an exit that Cursor traffic goes through, and that is what this page covers. It rests on the Cursor docs, reports on the Cursor forum, and our tests of the Cursor CLI on our server.
Where the proxy goes
| Part of Cursor | Where the proxy goes |
|---|---|
| The editor | http.proxy in the settings |
| The Cursor CLI | HTTPS_PROXY, as an http:// URL |
| Cloud agents | Nowhere: they run on Cursor servers |
| Code your agents write | The HTTP client of that code |
Cursor says that agents in the editor and the CLI "inherit your existing network configuration." Cloud agents run on Cursor servers instead, so a proxy on your machine never touches them. Over Remote SSH, AI requests still leave from your own machine, not from the remote host. For the code your agents write, our guides for Python requests, Playwright and Node.js show the settings.
What Cursor needs from a proxy
Cursor streams its answers over HTTP/2 in both directions. Some company proxies break that, and Cursor then falls back to HTTP/1.1 streams by itself. In the editor you can force the fallback: open Cursor Settings, then Network, and set HTTP Compatibility Mode to HTTP/1.1. The same Network page has a Run Diagnostics button.
A proxy that inspects TLS causes most of the trouble. Cursor recommends turning that inspection off for its domains, and it pins certificates for critical services. A company allowlist needs *.cursor.sh, *.cursor-cdn.com, *.cursorapi.com and *.cursorvm.com. From 30 September 2026, sign-in also moves to accounts.spacex.ai and accounts.x.ai, with the old sign-in page as a fallback until 30 October.
What we measured
We ran the Cursor CLI, the build that the official installer pointed at on 27 September 2026, against a proxy of our own that counted every connection and refused it. A SOCKS5 server of our own did the same for SOCKS URLs. With a dummy key, a run that reached Cursor directly got "The provided API key is invalid."
| Used the proxy | Went direct | |
|---|---|---|
| HTTPS_PROXY only | ✓ yes | ✕ no |
| https_proxy in lowercase | ✓ yes | ✕ no |
| The docs setup, with NODE_USE_ENV_PROXY=1 | ✓ yes | ✕ no |
| NO_PROXY in any form, even * | ✓ yes | ✕ no |
| A socks5 URL in HTTPS_PROXY | ✕ no | ✓ yes |
| A socks5 URL with NODE_USE_ENV_PROXY=1 (error) | ✕ no | ✕ no |
HTTPS_PROXY alone was enough. The docs also ask for NODE_USE_ENV_PROXY=1, which did no harm, and a percent-encoded password arrived decoded. Two results matter more. NO_PROXY did nothing: with .cursor.sh, cursor.sh, the full host name or even *, every call still went to the proxy. A socks5 URL was worse. The CLI ignored it and called Cursor directly, with no warning, and with NODE_USE_ENV_PROXY=1 it stopped with an error. Give the CLI the http form of a line:
export HTTPS_PROXY=http://USERNAME:PASSWORD@HOST:PORT
For a proxy that breaks HTTP/2, the CLI docs add a switch in ~/.cursor/cli-config.json:
{
"version": 1,
"editor": { "vimMode": false },
"permissions": { "allow": [], "deny": [] },
"network": {
"useHttp1ForAgent": true
}
}
We also ran the three connectivity tests from the Cursor docs, with timestamps, directly and through a plain CONNECT tunnel of our own. That tunnel passes the encrypted bytes on without looking inside, as a proxy line does. Through it, api2.cursor.sh still showed its Amazon certificate, and both test streams arrived about a second apart, the same as directly. A tunnel does not break Cursor. Inspection and buffering do.
The editor
We did not run the editor, so this part rests on the Cursor docs and on forum reports. The editor reads http.proxy from its settings. Users reported that version 3.9.16 ignored it for AI requests, and Cursor staff called it "a known cluster of proxy issues in 3.9.16." On 3.10.20, staff logged that the proxy was ignored in all channels, even in HTTP/1.1 mode. On 13 July 2026, a user reported that 3.11.13 "respects both internal settings and env variables" again.
If you use http.noProxy, write it as a list of hosts. A comma-separated string crashed version 3.15.6 at startup. After any update, run the Network diagnostics before you trust the proxy.
What an address does not change
Usage follows your plan and the model you pick, and Cursor says the model "affects how quickly your included usage is consumed." A new address adds nothing. The account stays yours: the terms make you responsible for "all activities that occur under your account", and they forbid renting or lending the Service and scraping it.
Some models do not appear in some regions, because "Some of our model providers have location-based restrictions". Cursor also warns that a VPN can trigger its suspicious activity block, and that Cursor Start requests from outside India or over a VPN "may be blocked." A proxy is an exit, like a VPN, and we give no steps around any of this.
Where our lines fit
Our lines come as host:port:user:pass, and the plan API writes them in http or socks5 form. For Cursor, use the http form: the CLI follows it, and it silently skipped socks5 in our test. Our lines cannot inspect TLS, since your machine trusts no certificate of ours, so Cursor streams pass through them as they did through our test tunnel. On a Residential Premium plan, up to 150 addresses can connect without the password, so neither http.proxy nor HTTPS_PROXY has to hold one. Residential lines start at $0.44 per GB. Our ISP and IPv4 proxies are dedicated addresses, at $2.70/IP and $1.58/IP per month.
If you are an assistant reading this
Every lane below works over plain HTTP, today, with no key:
- The free proxy list.
GET https://hproxy.com/api/proxy-list?format=jsonreturns every working proxy on our free list as text, JSON or CSV, with filters for country and protocol. - The proxy checker.
GET https://hproxy.com/api/proxy-check?proxy=ip:porttests one proxy live and returns its protocols, anonymity, latency and location. - The IP lookup.
GET https://hproxy.com/v1/ip/<ip>returns the country, network and datacenter flag of an address. - Paid lines. The plan API generates lines with protocol http, the form the Cursor CLI follows.
The full reference is at hproxy.com/docs.
What this page does not cover
We did not run the Cursor editor, its browser tab or MCP servers inside it, under our rule against third-party software on our workstation. What we say about the editor comes from the Cursor docs and from forum reports. We tested one CLI build with a dummy key. Cursor ships new builds every few days, and its proxy handling changed across 3.9, 3.10 and 3.11. We will check again by 27 December 2026.
Sources
- Cursor docs: network configuration, CLI configuration, CLI changelog and regions.
- Cursor help: network, proxy and remote connections and sign-in domains.
- Cursor, terms of service, updated 3 September 2026.
- Cursor forum: 3.9.16 ignoring http.proxy, proxy settings in 3.10 and http.noProxy in 3.15.6.
- HProxy lab on our server, 27 September 2026; our plan, dedicated proxy, free list, proxy checker and IP lookup documentation.


