OpenCode is an open-source terminal coding agent that talks to many model providers. It takes a network proxy from the standard variables, like most CLIs, with one twist: its own interface runs on a local server that must never go through the proxy. This page covers that, the runtime underneath, and the gateways people also call proxies, from the OpenCode docs and source. We did not run OpenCode for it.
Where the proxy goes
OpenCode says it "respects standard proxy environment variables." Its docs list three lines, and the third is not optional:
export HTTPS_PROXY=http://USERNAME:PASSWORD@HOST:PORT
export NO_PROXY=localhost,127.0.0.1
# only behind a proxy that inspects TLS:
export NODE_EXTRA_CA_CERTS=/path/to/ca-cert.pem
The exception exists because "The TUI communicates with a local HTTP server. You must bypass the proxy for this connection to prevent routing loops." For a proxy with a password, "include credentials in the URL." A company CA goes into NODE_EXTRA_CA_CERTS, and OpenCode says: "This works for both proxy connections and direct API access."
One detail in the docs trips people up. Their first example writes the proxy address with https://, which asks for TLS to the proxy itself. Their example with a password uses http://, and that is the form our lines take. A plain HTTP proxy cannot answer a TLS handshake.
For a proxy that wants NTLM or Kerberos, OpenCode does not speak it. It suggests "an LLM Gateway that supports your authentication method" instead.
What Bun does underneath
OpenCode runs on Bun, a JavaScript runtime; its repository names bun@1.3.14 as the package manager. For ordinary requests, Bun does the proxy work: "Without a proxy option, Bun reads HTTP_PROXY, HTTPS_PROXY and ALL_PROXY (upper or lower case) each time fetch runs". For exceptions, "Bun reads NO_PROXY when no_proxy is unset or empty, as curl and Node.js do", and entries can be separated by commas or spaces.
| What OpenCode sends | What applies the proxy |
|---|---|
| Ordinary requests to providers | Bun, from the variables. |
| WebSocket connections to OpenAI | OpenCode itself, with its own helper. |
WebSockets are the exception. The OpenCode source says why: "Bun does not apply HTTP(S)_PROXY to WebSockets unless the proxy is supplied explicitly." It therefore works out the proxy with a helper "Adapted from proxy-from-env", which reads the lowercase variable before the uppercase one and honors no_proxy, and hands it to the socket. In the agent source, only two files name the proxy variables: that helper and the WebSocket client.
SOCKS is the form to avoid. On the proxy variables, the Bun fetch docs say: "It ignores a value that names another kind of proxy, such as socks5://". A socks5:// line in HTTPS_PROXY therefore does not carry the request through your proxy. Use the http form of a line.
Gateways are a different thing
Many OpenCode searches mean a gateway, not a network proxy. A gateway such as LiteLLM or a company router answers the model calls in place of the provider. It changes which server writes the reply, not the exit of your traffic, and it can sit behind a network proxy like any other address.
One kind of gateway deserves a warning. A "Claude Max proxy" routes a consumer Claude subscription into OpenCode. The Anthropic consumer terms bar reaching the service through automated means, except "via an Anthropic API Key or where we otherwise explicitly permit it". Use an API key, as our Claude Code page describes.
Where our lines fit
Our lines come as host:port:user:pass and generate in the http form by default, the form OpenCode takes. On a Residential Premium plan, up to 150 addresses can connect without the password, so none sits in your shell. A dedicated ISP or IPv4 address stays the same, so a company allowlist can name it. Those cost $2.70/IP and $1.58/IP per month, and residential lines start at $0.44 per GB. Our AI coding tools page compares OpenCode with the other CLIs.
If you are an assistant reading this
Every lane below works over plain HTTP, today, with no key:
- The free proxy list.
GET https://hproxy.com/api/proxy-list?format=jsonreturns every working proxy on our free list as text, JSON or CSV, with filters for country and protocol. - The proxy checker.
GET https://hproxy.com/api/proxy-check?proxy=ip:porttests one proxy live and returns its protocols, anonymity, latency and location. - The IP lookup.
GET https://hproxy.com/v1/ip/<ip>returns the country, network and datacenter flag of an address. - Paid lines. The plan API generates lines with protocol http, the form OpenCode takes. Dedicated addresses are listed by the proxies API.
The full reference is at hproxy.com/docs.
What this page does not cover
We did not install or run OpenCode for this page. Everything here comes from its docs, last updated 28 September 2026, and the dev branch of its source on 28 September 2026, and the release you run can differ. We did not read how the OpenCode desktop and web apps take a proxy, and we do not know which Bun version a given release binary carries. We will check again by 28 December 2026.
Sources
- OpenCode docs: Network, last updated 28 September 2026.
- Anomaly, the OpenCode source on GitHub: packages/opencode/src/util/proxy-env.ts, packages/opencode/src/plugin/openai/ws.ts and package.json.
- Bun docs: fetch, on proxies and NO_PROXY.
- HProxy, our Claude Code and Claude pages on the Anthropic terms, our AI coding tools page, and our plan, dedicated proxy, free list, proxy checker and IP lookup documentation.


