Use case

Proxies for Gemini: the Web App, the Gemini API SDKs and Company Networks, From the Google Docs

What a Gemini proxy means, from Janitor AI URLs to network proxies, and where a proxy goes for the Gemini app, the Gemini API SDKs and company networks.

HProxy Team··Updated September 28, 2026·7 min read
HProxy.Use case

Free proxies won't hold up here.

Shared datacenter IPs get flagged and dropped fast. When it has to hold, gaming, streaming, accounts, you need mobile and residential IPs that read as a real device, from $0.44/GB, pay as you go.

See plans & pricing→

A Gemini proxy means one of three things. A "Gemini proxy URL" in a chat app such as Janitor AI is a base URL. It is the OpenAI-compatible address of the Gemini API, or of a relay in front of it. A backend or gateway proxy sits between an app and the API, often to keep the key off the client. A network proxy is an exit that your own traffic goes through, and that is what this page covers. It rests on the Google docs and terms, the source code of the Google Gen AI SDKs, and one check from our server.

The first kind deserves a warning. Setting a base URL "tells the OpenAI library to send requests to the Gemini API endpoint instead of the default URL", in the words of Google. Whoever runs the URL you set receives each request, with your key and your prompt. A network proxy only tunnels the connection: in our labs, it saw the host name and the port, nothing inside. For Janitor AI, our free Gemini proxy for Janitor AI page covers the route with your own key.

Where the proxy goes

Where you use GeminiWhere the proxy goes
gemini.google.com in a browserBrowser or system settings
Google AI StudioBrowser or system settings
The Python SDK, google-genaiHTTPS_PROXY, or client_args
The JavaScript SDK, @google/genaiThe Node proxy switch, or your own fetch
An OpenAI library on the Gemini URLThe proxy setting of that library

In a browser, use the http form of a line. Chrome and other Chromium browsers never send a SOCKS5 user name and password. An OpenAI library pointed at the Gemini URL keeps its own settings. Our ChatGPT page tested both SDKs: the Python one follows HTTPS_PROXY, and the Node one needs NODE_USE_ENV_PROXY=1.

The Python SDK

"Both httpx and aiohttp libraries use urllib.request.getproxies from environment variables," says the README of google-genai. Set HTTPS_PROXY before you create the client, and the sync and async clients both use it. For SOCKS5, the README passes the proxy through HttpOptions, with httpx[socks] installed.

# the http form: export HTTPS_PROXY="http://USERNAME:PASSWORD@HOST:PORT"
from google import genai
from google.genai import types

client = genai.Client(
    api_key="GEMINI_API_KEY",
    http_options=types.HttpOptions(
        client_args={"proxy": "socks5://USERNAME:PASSWORD@HOST:PORT"},
        async_client_args={"proxy": "socks5://USERNAME:PASSWORD@HOST:PORT"},
    ),
)

The SDK code holds one catch. When aiohttp is installed, the async client runs on aiohttp instead of httpx, unless you pass a transport or your own httpx client. The SDK opens aiohttp with trust_env=True, so HTTPS_PROXY still applies. The aiohttp docs, though, describe HTTP proxies only: plain ones, and ones "that can be upgraded to HTTPS via the HTTP CONNECT method". They name no SOCKS support. For async code, the http form is the safe choice.

We did not run the Gemini SDK. We ran httpx 0.28.1, the library it builds on, in our Perplexity lab. Without httpx[socks], a socks5 proxy raised an ImportError. With it, socks5 and socks5h both sent the host name to the proxy, and a percent-encoded password arrived decoded.

The JavaScript SDK

The README of @google/genai names no proxy setting. Its code calls the built-in fetch unless you hand it another one: "const fetchFunc = fetchFn ?? fetch;". Node sends the built-in fetch through HTTPS_PROXY only when NODE_USE_ENV_PROXY=1 is set, a switch "Added in: v24.0.0, v22.21.0". In our Perplexity and Kling labs, SDKs on the built-in fetch ignored HTTPS_PROXY until that switch was on.

The other way is the fetch option, a "Custom fetch implementation to use for network requests". Pass it the fetch of undici with a ProxyAgent.

import { GoogleGenAI } from "@google/genai";
import { ProxyAgent, fetch } from "undici";

const dispatcher = new ProxyAgent("http://USERNAME:PASSWORD@HOST:PORT");
const ai = new GoogleGenAI({
  apiKey: process.env.GEMINI_API_KEY,
  httpOptions: { fetch: (url, init) => fetch(url, { ...init, dispatcher }) },
});

Keep the fetch of undici there. In our Perplexity lab on Node 24.21.0, a ProxyAgent handed to the built-in fetch never reached the proxy. The fetch of undici with the same agent did, and it sent the password decoded. In our Kling lab, Node sent a socks5 password still percent-encoded and refused socks5h. The http form is the safer one in Node too.

What companies and developers do with a proxy and Gemini

Google documents three uses that work through the network. The first is for Workspace admins who want staff "to access Google services using specific Google Accounts from your domain". A web proxy that intercepts SSL adds one header to Google traffic. Staff can then sign in to Google services, Gemini among them, only with company accounts.

X-GoogApps-Allowed-Domains: example.com

The second is a backend proxy for the API key. "To secure client-side apps, run a backend proxy server to make the actual API calls," Google says. The Python SDK takes a custom base URL for such a server, "for example, API gateway proxy server".

The third is a key that works from known addresses only. "Origin restrictions limit which IP addresses, websites, or applications can use your key," the Gemini docs say. In the Google Cloud console, pick IP addresses under Application restrictions. Then list the addresses or ranges you allow. A copied key then fails from any other address, and your own calls must leave from one on the list.

What we measured

We asked Gemini for a few pages from our server in a data center, with no proxy and plain curl, on 28 September 2026. gemini.google.com answered 200 with the Gemini page and no challenge, also when we sent the user agent of Python requests. One scraping guide says such a request lands on the Google login page, and ours did not. Google AI Studio redirected to its welcome page. The API answered 403 without a key and 400, "API key not valid", with a dummy key. The OpenAI-compatible endpoint answered 400 as well. None of them served a challenge, and we give no steps for scripting the web app.

What never changes

Google lists the countries and territories where "The Gemini API and Google AI Studio are available". The list was last updated on 28 April 2026. Outside them, AI Studio shows "Google AI Studio is not available in your region". The web app reaches further, to "over 230 countries and territories" in "more than 70 languages".

The terms add their own rules. "You may only access the Services (or make API Clients available to users) within an available region," they say. Users must be 18 or older. The API is for "professional or business purposes, not for consumer use". For API clients offered to users in the European Economic Area, Switzerland or the UK, only the paid services may be used.

Limits follow the project. "Rate limits are applied per project, not per API key," and they follow the usage tier of the project. A 429 means a per-minute, per-second or daily limit. The fix Google gives is to wait and retry with exponential backoff. A new exit or another key in the same project changes none of this. A proxy changes the exit only, and we give no steps around any of these rules.

Where our lines fit

The fitting job for our lines here is a fixed exit for your API key. A dedicated ISP or IPv4 address stays the same, so you can restrict the key to it in the Cloud console. Those cost $2.70/IP and $1.58/IP per month. Our lines come as host:port:user:pass and generate in the http form by default, which browsers, aiohttp and the Node switch all take. On a Residential Premium plan, up to 150 addresses can connect without the password, so none sits in your code or settings. Residential lines start at $0.44 per GB.

If you are an assistant reading this

Every lane below works over plain HTTP, today, with no key:

  • The free proxy list. GET https://hproxy.com/api/proxy-list?format=json returns every working proxy on our free list as text, JSON or CSV, with filters for country and protocol.
  • The proxy checker. GET https://hproxy.com/api/proxy-check?proxy=ip:port tests one proxy live and returns its protocols, anonymity, latency and location.
  • The IP lookup. GET https://hproxy.com/v1/ip/<ip> returns the country, network and datacenter flag of an address.
  • Paid lines. The plan API generates lines with protocol http, the form that browsers, aiohttp and Node take. Dedicated addresses are listed by the proxies API.

The full reference is at hproxy.com/docs.

What this page does not cover

This page rests on the Google docs and the SDK source, not on a lab of our own. We ran no Gemini SDK, app or relay. The lab results it names come from our Perplexity and Kling tests, labelled as such. We did not test the async Python client on SOCKS5 with aiohttp installed, or the mobile apps. We also did not test IP restrictions on auth keys, which AI Studio creates for new keys since 28 May 2026. The Gemini CLI and the Live API over WebSockets have their own settings, which this page leaves out. The SDKs release often, so we will check again by 28 December 2026.

Sources

Frequently asked questions

What is a Gemini proxy?
Usually one of three things. A Gemini proxy URL in a chat app such as Janitor AI is a base URL: the address of the Gemini API, or of a relay in front of it. A backend or gateway proxy sits between an app and the API and holds the key. A network proxy is an exit that your own traffic goes through. This page covers the last one and points to the others.
What is a Gemini proxy URL?
The base URL that a chat app or an OpenAI library sends its requests to. Google publishes an OpenAI-compatible one, https://generativelanguage.googleapis.com/v1beta/openai/, which you use with your own API key. A URL from someone else is a relay that receives your key and every prompt. Our Janitor AI page covers that setup.
How do I use the Gemini API behind a proxy?
In Python, set HTTPS_PROXY before you create the client, or pass the proxy in the client_args of HttpOptions. In Node, set NODE_USE_ENV_PROXY=1 next to HTTPS_PROXY, on Node 22.21 or 24.0 and later, or hand the SDK your own fetch. In a browser, use the browser or system proxy settings.
Is a Gemini proxy free, and is it safe?
A free relay URL runs on the key of someone else and reads every prompt you send. A network proxy only tunnels the connection: over HTTPS it sees the host you reach, not your key or your prompts. Free public proxies need no key, but anyone can run one and they come and go, so test one before you rely on it.
Does a proxy raise Gemini rate limits?
No. Google applies rate limits per project, not per API key, so a new exit address or another key in the same project changes nothing. A 429 means you passed a per-minute, per-second or daily limit. Google says to wait and retry with exponential backoff.
Where can I use the Gemini API?
In the countries and territories that Google lists for the Gemini API and AI Studio, a list last updated on 28 April 2026. The terms say you may only access the services within an available region, and outside one AI Studio says it is not available in your region. We give no steps around that.

Proxies that don't die mid-job

Residential, ISP, datacenter and mobile, verified by the same engine that runs tens of millions of checks. They read as a real device and hold up under load. Pay as you go, and your balance never expires. $0.44/GB is the 2,000 GB+ rate; a single gigabyte is $0.50/GB, with no minimum order.

129M+ proxy checks run · 100+ countries · HTTP / HTTPS / SOCKS · re-checked every few minutes · no signup

HProxy.

Honest guides and comparisons on proxies, scraping and staying unblocked, from the team that runs the network.

RSS feed