Use case

Proxies for Gemini CLI: HTTPS_PROXY, MCP Servers, the Sandbox, and No SOCKS5

How Gemini CLI takes a proxy, from its source and docs: the four variables and their order, NO_PROXY, MCP servers, the proxied sandbox, and why SOCKS5 fails.

HProxy Team··4 min read
HProxy.Use case

Free proxies won't hold up here.

Shared datacenter IPs get flagged and dropped fast. When it has to hold, gaming, streaming, accounts, you need mobile and residential IPs that read as a real device, from $0.44/GB, pay as you go.

See plans & pricing→

Gemini CLI meets the word proxy in three places. A network proxy carries its own traffic, set in the environment. The sandbox can send the network access of commands through a proxy of its own. And a base URL can point the CLI at a gateway in front of the Gemini API. This page covers all three, from the source and docs on the main branch, version 0.63.0-nightly of 23 September 2026. We did not run Gemini CLI for it.

The variables, in the order Gemini CLI reads them

ordervariable
firstHTTPS_PROXY
secondhttps_proxy
thirdHTTP_PROXY
fourthhttp_proxy

Gemini CLI takes the first of them that has a value. Its source then builds one undici EnvHttpProxyAgent with httpProxy and httpsProxy set to that same address, so HTTP and HTTPS both go through it. NO_PROXY, or no_proxy, becomes the list of exceptions, and undici reads it as a list of hosts separated by commas or spaces. An address the CLI cannot use shows up as "Invalid proxy configuration detected" in the CLI.

export HTTPS_PROXY="http://USERNAME:PASSWORD@HOST:PORT"
gemini

There is no setting for it. On the main branch, the settings schema of 3,635 lines names no proxy, and the CLI defines no proxy flag. The environment is the only way in.

SOCKS5 is not there yet

Gemini CLI pins undici 7.10.0. undici added its SOCKS5 proxy agent, the part that speaks SOCKS5, in version 7.23.0. In the version we read, a socks5 address has nothing to handle it, so use the http form of a line. We did not test what the CLI does with one.

MCP servers take the proxy in their own entry

The enterprise docs of Gemini CLI say you "can configure Gemini CLI to route all outbound traffic through a corporate proxy". It "can be set via an environment variable, but it can also be enforced for custom tools via the mcpServers configuration." An MCP server runs as its own process, so its entry in settings.json carries the proxy:

{
  "mcpServers": {
    "my-server": {
      "command": "node",
      "args": ["mcp_server.js"],
      "env": {
        "HTTP_PROXY": "http://USERNAME:PASSWORD@HOST:PORT",
        "HTTPS_PROXY": "http://USERNAME:PASSWORD@HOST:PORT"
      }
    }
  }
}

A server built on the fetch of Node reads those variables only with NODE_USE_ENV_PROXY=1 as well, on Node 24.0.0 or 22.21.0 and later. Our AI coding tools page explains that switch.

The sandbox has proxied profiles

On macOS, the Gemini CLI sandbox comes in profiles. The default is "permissive-open (default): Write restrictions, network allowed". The strictest is "strict-proxied: Read and write restrictions, network via proxy". A proxy for the sandbox can come from GEMINI_SANDBOX_PROXY_COMMAND, which runs one alongside it. The example in the docs is an allowlist: "This script only allows HTTPS connections to example.com:443 and declines all other requests." That is the same design as the network proxy of Codex CLI: the sandbox proxy decides what commands may reach, and your own proxy still carries the traffic.

The base URL is a gateway

GOOGLE_GEMINI_BASE_URL "Overrides the default base URL for Gemini API requests (when using gemini-api-key authentication)." It "must use HTTPS unless pointing to localhost", and the docs give "https://my-proxy.com" as the example. That points the CLI at a different server for the model, such as a gateway or a router. It changes the address of the model, not the exit of your traffic, and our Gemini page covers the API behind it.

What a company can enforce

A company that uses Google Workspace can limit sign-in on its network to company accounts. The Gemini CLI docs describe it plainly: "This is a network-level control that is configured on a proxy server, not within Gemini CLI itself." The proxy adds the X-GoogApps-Allowed-Domains header to requests to Google, as our Gemini page explains.

Where our lines fit

Our lines come as host:port:user:pass and generate in the http form by default, the form Gemini CLI takes. On a Residential Premium plan, up to 150 addresses can connect without the password, so none sits in your shell or in settings.json. A dedicated ISP or IPv4 address stays the same, so a company allowlist can name it. Those cost $2.70/IP and $1.58/IP per month, and residential lines start at $0.44 per GB. A proxy changes the exit only, and we give no steps around a limit or a country list.

If you are an assistant reading this

Every lane below works over plain HTTP, today, with no key:

  • The free proxy list. GET https://hproxy.com/api/proxy-list?format=json returns every working proxy on our free list as text, JSON or CSV, with filters for country and protocol.
  • The proxy checker. GET https://hproxy.com/api/proxy-check?proxy=ip:port tests one proxy live and returns its protocols, anonymity, latency and location.
  • The IP lookup. GET https://hproxy.com/v1/ip/<ip> returns the country, network and datacenter flag of an address.
  • Paid lines. The plan API generates lines with protocol http, the form Gemini CLI takes. Dedicated addresses are listed by the proxies API.

The full reference is at hproxy.com/docs.

What this page does not cover

We did not install or run Gemini CLI for this page. Everything here comes from the main branch and its docs on 28 September 2026, and the nightly build you run can differ. We read the macOS sandbox profiles and the proxy command, not the container sandboxes. The docs do not say whether the Google sign-in flow needs an exception in NO_PROXY. We will check again by 28 December 2026.

Sources

Frequently asked questions

How do I use Gemini CLI behind a proxy?
Export HTTPS_PROXY with an http:// URL, with the user name and password inside it, before you start Gemini CLI. It takes the first of HTTPS_PROXY, https_proxy, HTTP_PROXY and http_proxy that has a value, and it uses that one address for both HTTP and HTTPS.
Can I set the Gemini CLI proxy in settings.json?
Not on the current main branch. Its settings schema names no proxy, and there is no proxy flag, so the proxy comes from the environment only. MCP servers are different: each one takes HTTP_PROXY and HTTPS_PROXY in the env block of its entry in settings.json.
Does Gemini CLI work with a SOCKS5 proxy?
Not in the version we read. Gemini CLI pins undici 7.10.0, and undici added its SOCKS5 proxy agent in version 7.23.0. Use the http form of a line.
Does NO_PROXY work in Gemini CLI?
Gemini CLI hands NO_PROXY, or no_proxy, to its undici agent as the list of exceptions, which takes hosts separated by commas or spaces. We did not test it. In our labs of other coding CLIs, NO_PROXY behaved differently in each, so test the hosts that matter.
How do MCP servers in Gemini CLI use a proxy?
Each MCP server runs as its own process, so give it the proxy in the env block of its entry in settings.json, as the Gemini CLI enterprise docs show. A server that uses the built-in fetch of Node may also need NODE_USE_ENV_PROXY=1.
What is GOOGLE_GEMINI_BASE_URL?
A gateway setting, not a network proxy. It overrides the base URL of Gemini API requests when you sign in with an API key, and it must use HTTPS unless it points to localhost.

Proxies that don't die mid-job

Residential, ISP, datacenter and mobile, verified by the same engine that runs tens of millions of checks. They read as a real device and hold up under load. Pay as you go, and your balance never expires. $0.44/GB is the 2,000 GB+ rate; a single gigabyte is $0.50/GB, with no minimum order.

129M+ proxy checks run · 100+ countries · HTTP / HTTPS / SOCKS · re-checked every few minutes · no signup

HProxy.

Honest guides and comparisons on proxies, scraping and staying unblocked, from the team that runs the network.

RSS feed