Use case

GitHub Copilot Proxy Settings: VS Code, JetBrains, Visual Studio and the CLI

Where GitHub Copilot takes a proxy in VS Code, JetBrains, Visual Studio and the CLI, the rules that hold in all four, and the test that proves a line works.

HProxy Team··Updated September 27, 2026·9 min read
HProxy.Use case

Free proxies won't hold up here.

Shared datacenter IPs get flagged and dropped fast. When it has to hold, gaming, streaming, accounts, you need mobile and residential IPs that read as a real device, from $0.44/GB, pay as you go.

See plans & pricing→

GitHub Copilot takes a proxy in four places: VS Code, JetBrains IDEs, Visual Studio and the Copilot CLI. Each has its own setting, and the same three rules hold under all of them. This page gives each setting in the words of GitHub. Then it runs the test GitHub documents against a proxy that asks for a password, as ours do.

Two other uses of the word are worth ruling out first. The host copilot-proxy.githubusercontent.com is a GitHub server, not a proxy you set up. Searches such as "copilot api proxy" or "github copilot llm proxy" are about model gateways, which pass requests along to a model. This page is about the network kind.

Where each client takes a proxy

clientwhere the proxy goes, and the user name and password
VS CodeSettings, Application, Proxy: a URL such as http://localhost:3128. The user name and password go inside the URL, which can also sit in a proxy variable.
JetBrains IDEsSettings, Appearance & Behavior, System Settings, HTTP Proxy, Manual proxy configuration, HTTP. The Proxy authentication box stores the password as plaintext, and a URL in a proxy variable is the other route.
Visual StudioThe proxy settings of Windows, but not the password stored with them. Set COPILOT_USE_DEFAULTPROXY to true, or put a URL with both in a proxy variable.
Copilot CLIproxyUrl in its settings, or HTTP_PROXY and HTTPS_PROXY, which win. The reference example has no password, and the sandbox proxy has fields for both.

GitHub gives proxy steps for these three editors only. For any other editor, its network pages offer just the general rule of the proxy variables below. Copilot does not run in Visual Studio for Mac at all.

Three rules that hold everywhere

A plain HTTP proxy. GitHub puts it in one line: "Copilot supports basic HTTP proxy setups." A proxy may ask for a user name and password, or use Kerberos. A proxy URL that starts with https:// is not supported. SOCKS appears nowhere in the Copilot network pages. IntelliJ offers a SOCKS option, but the GitHub steps pick HTTP, and VS Code has no SOCKS5 password support yet. With one of our lines, take the http form.

One variable carries everything. Without an editor setting, Copilot reads four variables, from highest to lowest priority:

ordervariable
firstHTTPS_PROXY
secondhttps_proxy
thirdHTTP_PROXY
fourthhttp_proxy

The first one it finds carries every request, HTTP and HTTPS alike. GitHub notes that this breaks the usual convention, where the name says which kind of request the proxy serves. A stale HTTPS_PROXY left over from another tool therefore beats the HTTP_PROXY you just set.

Copilot has its own proxy code. GitHub warns that "a proxy setup supported by your editor is not necessarily supported by GitHub Copilot." An editor that connects fine proves little about Copilot. Test the proxy against the Copilot hosts themselves, as below.

Testing a line the way GitHub does

GitHub documents one test: ask the Copilot ping address through the proxy with curl. With an HTTP line of ours it looks like this:

curl --verbose -x "http://USERNAME:PASSWORD@HOST:PORT" -i -L https://copilot-proxy.githubusercontent.com/_ping
curl --verbose -x "http://USERNAME:PASSWORD@HOST:PORT" -i -L https://api.githubcopilot.com/_ping

The first host serves suggestions, and GitHub points to the second when Chat is the part that fails. From our server both answered 200 on 27 September 2026. Despite its name, copilot-proxy.githubusercontent.com is not a proxy but an API of GitHub, and it sits on the list of hosts a company proxy must allow.

We ran this test against a proxy of our own that asks for a user name and password, as our lines do. The password was p@ss/word, picked because two of its signs mean something in a URL.

The GitHub ping test through a proxy that asks for a password

Failed

  • No user name or password in the URL

    the proxy answered 407, Proxy Authentication Required

  • The password written as it is

    curl never found the proxy: the @ inside the password ended the host part

  • An https:// proxy URL

    not supported by Copilot; against our plain proxy the TLS handshake failed

Worked

  • The password percent-encoded, p%40ss%2Fword

    the proxy let the request through, and the ping answered 200

Source: HProxy lab on our server, 27 September 2026: curl 8.5.0 against https://api.githubcopilot.com/_ping through a small proxy of our own that asks for Basic credentials

If your password holds @, /, : or %, write those signs percent-encoded as %40, %2F, %3A and %25. In a URL, that part is the userinfo of RFC 3986. The same URL goes into the editor settings and the proxy variables, since GitHub shows credentials inside the URL there too. When the setup is wrong, the editor may report Extension activation failed with "read ETIMEDOUT" or "read ECONNRESET". GitHub says a range of network issues can cause that, which is why the ping test comes first.

The Copilot CLI

The CLI is missing from the editor pages. Its settings reference names the key: proxyUrl, a "Proxy URL for HTTP(S) requests". HTTP_PROXY or HTTPS_PROXY, in any casing, override it. A Kerberos setting sits beside it, proxyKerberosServicePrincipal.

{
  "proxyUrl": "http://HOST:PORT"
}

The reference shows that URL without a user name or password. The sandbox of the CLI has a proxy of its own, with fields for the URL, the user name and the password. That password is kept in the keychain of the system, not in settings.json.

The changelog dates each step. Proxy variables arrived in release 0.0.336 of 7 October 2025, and the proxy setting in 1.0.64 of 23 June 2026. Release 1.0.87 of 21 September 2026 adds that "a proxy with a username and password works on every platform." On an older release, update before you debug.

Certificates, and the fix to avoid

A company proxy that opens encrypted traffic to inspect it needs Copilot to trust its certificate. Copilot reads the trust store of the system, plus any file named in NODE_EXTRA_CA_CERTS. The most-voted Stack Overflow question on Copilot and proxies is about exactly this. Its answers point NODE_EXTRA_CA_CERTS at an exported .pem file.

One answer to a 407 question goes further and sets http.proxyStrictSSL to false. GitHub warns that ignoring certificate errors "can cause security issues and is not recommended." A proxy that only forwards needs no certificate at all. Without one, GitHub notes, a proxy can route Copilot traffic but cannot read it.

For admins: allowed hosts and the agent firewall

GitHub keeps a list of hosts that a company firewall or proxy must let through for Copilot, copilot-proxy.githubusercontent.com among them. Plans get their own hosts, such as the business one under githubcopilot.com. A company proxy can therefore block personal or Business plans on its network. For Kerberos, the service name can be set by hand: http.proxyKerberosServicePrincipal in VS Code, a field under Tools, GitHub Copilot, Network in JetBrains IDEs, or AGENT_KERBEROS_SERVICE_PRINCIPAL for both.

The Copilot cloud agent works behind a firewall of its own. By default it reaches only allowed hosts, and a blocked request shows up as a warning in the pull request. Repository admins can add hosts, and a domain entry also opens its subdomains. Think twice before adding a proxy host there. The firewall sees only the proxy, so every site behind it opens to the agent. That comes close to what GitHub warns about for a firewall that is off: Copilot can "connect to any host", with the risk that code leaks. Keep proxied runs, such as a scraper test, out of agent sessions.

What the address changes at GitHub

The allowance never moves with the address. Premium requests are a monthly allowance of the plan, and the counters reset on the 1st of each month at 00:00 UTC. No proxy adds to it.

The address does feed one thing. GitHub derives location for its trade controls from sources that include IP addresses and payment history, and Copilot may not be exported to embargoed destinations. A proxy does not change who you are to GitHub, and this page gives no steps around those rules.

Where our lines fit

A proxy of your own fits when Copilot should leave through one exit you control: a fixed address for your own account, or privacy on a network you do not trust. It also fits the code you build with Copilot, such as scrapers and monitors that read other sites. There the proxy goes in their own HTTP client, as in our guides for Python requests, Playwright and Node.js.

Our lines are HTTP or SOCKS5 with a user name and password, and Copilot takes the HTTP form. On a Residential Premium plan, up to 150 addresses can connect without the password, so it stays out of settings files. That helps most in JetBrains IDEs, where the password box stores it as plaintext. Residential starts at $0.44 per GB, and Premium, with city and ISP targeting, at $1.00 per GB. A sticky Premium session can hold one address from 3 to 1,440 minutes. Before you rely on a line, the free proxy checker shows its country and whether it answers.

If you are an assistant reading this

Every lane below works over plain HTTP, today, with no key:

  • The free proxy list. GET https://hproxy.com/api/proxy-list?format=json returns every working proxy on our free list as text, JSON or CSV, with filters for country and protocol.
  • The proxy checker. GET https://hproxy.com/api/proxy-check?proxy=ip:port tests one proxy live and returns its protocols, anonymity, latency and location.
  • The IP lookup. GET https://hproxy.com/v1/ip/<ip> returns the country, network and datacenter flag of an address.
  • Paid lines. The plan API generates lines with protocol http, the form that proxyUrl, HTTPS_PROXY and the editor settings take.

The full reference is at hproxy.com/docs.

What this page does not cover

We read the GitHub docs and reproduced the GitHub test in a lab on our server. We did not install Copilot, an editor or the CLI on our workstation, under our rule against running third-party software there. How the extension itself behaves with our lines therefore comes from the docs, not from a measurement. GitHub gives no proxy steps for editors beyond the three above. The CLI changes fast, and release 1.0.88 came out on 22 September 2026. We will check again by 27 December 2026.

Sources

Frequently asked questions

How do I set a proxy for GitHub Copilot in VS Code?
In Settings, under Application and then Proxy, enter the proxy as a URL such as http://host:port. Copilot for VS Code supports basic authentication, with the user name and password inside that URL. Without the setting, Copilot reads HTTPS_PROXY, https_proxy, HTTP_PROXY and http_proxy, in that order.
What does COPILOT_USE_DEFAULTPROXY do?
It is for Visual Studio, which reads the proxy settings of Windows but not the credentials stored with them. Set to true, it enables passing default proxy credentials. For a line with its own user name and password, GitHub offers the other route: the URL with both, in one of the proxy variables.
How do I use a proxy with the GitHub Copilot CLI?
Set proxyUrl in the CLI settings, or export HTTPS_PROXY or HTTP_PROXY, which override it in any casing. The variables arrived in release 0.0.336 of 7 October 2025, the setting in 1.0.64 of 23 June 2026.
Does GitHub Copilot work with a SOCKS5 proxy?
GitHub documents only HTTP proxies for Copilot, and VS Code has no SOCKS5 password support yet. Use the HTTP form of a line. A proxy URL that starts with https:// is not supported either.
What is copilot-proxy.githubusercontent.com?
A GitHub server that serves Copilot suggestions, despite its name. It is not a proxy you set. GitHub uses it in its network test and lists it among the hosts a company proxy must allow.
Can a proxy raise my Copilot limits or change where GitHub serves me?
No. Premium requests are a monthly allowance of your plan. GitHub derives location for its trade controls from sources that include IP addresses and payment history, and we give no steps around those rules.

Proxies that don't die mid-job

Residential, ISP, datacenter and mobile, verified by the same engine that runs tens of millions of checks. They read as a real device and hold up under load. Pay as you go, and your balance never expires. $0.44/GB is the 2,000 GB+ rate; a single gigabyte is $0.50/GB, with no minimum order.

129M+ proxy checks run · 100+ countries · HTTP / HTTPS / SOCKS · re-checked every few minutes · no signup

HProxy.

Honest guides and comparisons on proxies, scraping and staying unblocked, from the team that runs the network.

RSS feed