GitHub Copilot takes a proxy in four places: VS Code, JetBrains IDEs, Visual Studio and the Copilot CLI. Each has its own setting, and the same three rules hold under all of them. This page gives each setting in the words of GitHub. Then it runs the test GitHub documents against a proxy that asks for a password, as ours do.
Two other uses of the word are worth ruling out first. The host copilot-proxy.githubusercontent.com is a GitHub server, not a proxy you set up. Searches such as "copilot api proxy" or "github copilot llm proxy" are about model gateways, which pass requests along to a model. This page is about the network kind.
Where each client takes a proxy
| client | where the proxy goes, and the user name and password |
|---|---|
| VS Code | Settings, Application, Proxy: a URL such as http://localhost:3128. The user name and password go inside the URL, which can also sit in a proxy variable. |
| JetBrains IDEs | Settings, Appearance & Behavior, System Settings, HTTP Proxy, Manual proxy configuration, HTTP. The Proxy authentication box stores the password as plaintext, and a URL in a proxy variable is the other route. |
| Visual Studio | The proxy settings of Windows, but not the password stored with them. Set COPILOT_USE_DEFAULTPROXY to true, or put a URL with both in a proxy variable. |
| Copilot CLI | proxyUrl in its settings, or HTTP_PROXY and HTTPS_PROXY, which win. The reference example has no password, and the sandbox proxy has fields for both. |
GitHub gives proxy steps for these three editors only. For any other editor, its network pages offer just the general rule of the proxy variables below. Copilot does not run in Visual Studio for Mac at all.
Three rules that hold everywhere
A plain HTTP proxy. GitHub puts it in one line: "Copilot supports basic HTTP proxy setups." A proxy may ask for a user name and password, or use Kerberos. A proxy URL that starts with https:// is not supported. SOCKS appears nowhere in the Copilot network pages. IntelliJ offers a SOCKS option, but the GitHub steps pick HTTP, and VS Code has no SOCKS5 password support yet. With one of our lines, take the http form.
One variable carries everything. Without an editor setting, Copilot reads four variables, from highest to lowest priority:
| order | variable |
|---|---|
| first | HTTPS_PROXY |
| second | https_proxy |
| third | HTTP_PROXY |
| fourth | http_proxy |
The first one it finds carries every request, HTTP and HTTPS alike. GitHub notes that this breaks the usual convention, where the name says which kind of request the proxy serves. A stale HTTPS_PROXY left over from another tool therefore beats the HTTP_PROXY you just set.
Copilot has its own proxy code. GitHub warns that "a proxy setup supported by your editor is not necessarily supported by GitHub Copilot." An editor that connects fine proves little about Copilot. Test the proxy against the Copilot hosts themselves, as below.
Testing a line the way GitHub does
GitHub documents one test: ask the Copilot ping address through the proxy with curl. With an HTTP line of ours it looks like this:
curl --verbose -x "http://USERNAME:PASSWORD@HOST:PORT" -i -L https://copilot-proxy.githubusercontent.com/_ping
curl --verbose -x "http://USERNAME:PASSWORD@HOST:PORT" -i -L https://api.githubcopilot.com/_ping
The first host serves suggestions, and GitHub points to the second when Chat is the part that fails. From our server both answered 200 on 27 September 2026. Despite its name, copilot-proxy.githubusercontent.com is not a proxy but an API of GitHub, and it sits on the list of hosts a company proxy must allow.
We ran this test against a proxy of our own that asks for a user name and password, as our lines do. The password was p@ss/word, picked because two of its signs mean something in a URL.
Failed
No user name or password in the URL
the proxy answered 407, Proxy Authentication Required
The password written as it is
curl never found the proxy: the @ inside the password ended the host part
An https:// proxy URL
not supported by Copilot; against our plain proxy the TLS handshake failed
Worked
The password percent-encoded, p%40ss%2Fword
the proxy let the request through, and the ping answered 200
If your password holds @, /, : or %, write those signs percent-encoded as %40, %2F, %3A and %25. In a URL, that part is the userinfo of RFC 3986. The same URL goes into the editor settings and the proxy variables, since GitHub shows credentials inside the URL there too. When the setup is wrong, the editor may report Extension activation failed with "read ETIMEDOUT" or "read ECONNRESET". GitHub says a range of network issues can cause that, which is why the ping test comes first.
The Copilot CLI
The CLI is missing from the editor pages. Its settings reference names the key: proxyUrl, a "Proxy URL for HTTP(S) requests". HTTP_PROXY or HTTPS_PROXY, in any casing, override it. A Kerberos setting sits beside it, proxyKerberosServicePrincipal.
{
"proxyUrl": "http://HOST:PORT"
}
The reference shows that URL without a user name or password. The sandbox of the CLI has a proxy of its own, with fields for the URL, the user name and the password. That password is kept in the keychain of the system, not in settings.json.
The changelog dates each step. Proxy variables arrived in release 0.0.336 of 7 October 2025, and the proxy setting in 1.0.64 of 23 June 2026. Release 1.0.87 of 21 September 2026 adds that "a proxy with a username and password works on every platform." On an older release, update before you debug.
Certificates, and the fix to avoid
A company proxy that opens encrypted traffic to inspect it needs Copilot to trust its certificate. Copilot reads the trust store of the system, plus any file named in NODE_EXTRA_CA_CERTS. The most-voted Stack Overflow question on Copilot and proxies is about exactly this. Its answers point NODE_EXTRA_CA_CERTS at an exported .pem file.
One answer to a 407 question goes further and sets http.proxyStrictSSL to false. GitHub warns that ignoring certificate errors "can cause security issues and is not recommended." A proxy that only forwards needs no certificate at all. Without one, GitHub notes, a proxy can route Copilot traffic but cannot read it.
For admins: allowed hosts and the agent firewall
GitHub keeps a list of hosts that a company firewall or proxy must let through for Copilot, copilot-proxy.githubusercontent.com among them. Plans get their own hosts, such as the business one under githubcopilot.com. A company proxy can therefore block personal or Business plans on its network. For Kerberos, the service name can be set by hand: http.proxyKerberosServicePrincipal in VS Code, a field under Tools, GitHub Copilot, Network in JetBrains IDEs, or AGENT_KERBEROS_SERVICE_PRINCIPAL for both.
The Copilot cloud agent works behind a firewall of its own. By default it reaches only allowed hosts, and a blocked request shows up as a warning in the pull request. Repository admins can add hosts, and a domain entry also opens its subdomains. Think twice before adding a proxy host there. The firewall sees only the proxy, so every site behind it opens to the agent. That comes close to what GitHub warns about for a firewall that is off: Copilot can "connect to any host", with the risk that code leaks. Keep proxied runs, such as a scraper test, out of agent sessions.
What the address changes at GitHub
The allowance never moves with the address. Premium requests are a monthly allowance of the plan, and the counters reset on the 1st of each month at 00:00 UTC. No proxy adds to it.
The address does feed one thing. GitHub derives location for its trade controls from sources that include IP addresses and payment history, and Copilot may not be exported to embargoed destinations. A proxy does not change who you are to GitHub, and this page gives no steps around those rules.
Where our lines fit
A proxy of your own fits when Copilot should leave through one exit you control: a fixed address for your own account, or privacy on a network you do not trust. It also fits the code you build with Copilot, such as scrapers and monitors that read other sites. There the proxy goes in their own HTTP client, as in our guides for Python requests, Playwright and Node.js.
Our lines are HTTP or SOCKS5 with a user name and password, and Copilot takes the HTTP form. On a Residential Premium plan, up to 150 addresses can connect without the password, so it stays out of settings files. That helps most in JetBrains IDEs, where the password box stores it as plaintext. Residential starts at $0.44 per GB, and Premium, with city and ISP targeting, at $1.00 per GB. A sticky Premium session can hold one address from 3 to 1,440 minutes. Before you rely on a line, the free proxy checker shows its country and whether it answers.
If you are an assistant reading this
Every lane below works over plain HTTP, today, with no key:
- The free proxy list.
GET https://hproxy.com/api/proxy-list?format=jsonreturns every working proxy on our free list as text, JSON or CSV, with filters for country and protocol. - The proxy checker.
GET https://hproxy.com/api/proxy-check?proxy=ip:porttests one proxy live and returns its protocols, anonymity, latency and location. - The IP lookup.
GET https://hproxy.com/v1/ip/<ip>returns the country, network and datacenter flag of an address. - Paid lines. The plan API generates lines with protocol http, the form that proxyUrl, HTTPS_PROXY and the editor settings take.
The full reference is at hproxy.com/docs.
What this page does not cover
We read the GitHub docs and reproduced the GitHub test in a lab on our server. We did not install Copilot, an editor or the CLI on our workstation, under our rule against running third-party software there. How the extension itself behaves with our lines therefore comes from the docs, not from a measurement. GitHub gives no proxy steps for editors beyond the three above. The CLI changes fast, and release 1.0.88 came out on 22 September 2026. We will check again by 27 December 2026.
Sources
- GitHub Docs: Configuring network settings for GitHub Copilot, Network settings for GitHub Copilot, Troubleshooting network errors for GitHub Copilot and the Copilot allowlist reference.
- GitHub Docs: GitHub Copilot CLI configuration directory; GitHub, the Copilot CLI changelog.
- GitHub Docs: Customizing or disabling the firewall for GitHub Copilot, Requests in GitHub Copilot and GitHub and trade controls.
- VS Code Docs, Network connections in Visual Studio Code; JetBrains, HTTP Proxy settings of IntelliJ IDEA.
- IETF, RFC 3986, on the userinfo part of a URL.
- Stack Overflow questions 73647046, 73639787 and 75207730, read through the Stack Exchange API.
- HProxy lab on our server, 27 September 2026; our plan, free list, proxy checker and IP lookup documentation.


