Use case

Proxies for OpenCode: HTTPS_PROXY, the Local Server Exception, and What Bun Does Underneath

How OpenCode takes a proxy, from its docs and source: the variables, the NO_PROXY entry for its own server, company CAs, WebSockets under Bun, gateways.

HProxy Team··4 min read
HProxy.Use case

Free proxies won't hold up here.

Shared datacenter IPs get flagged and dropped fast. When it has to hold, gaming, streaming, accounts, you need mobile and residential IPs that read as a real device, from $0.44/GB, pay as you go.

See plans & pricing→

OpenCode is an open-source terminal coding agent that talks to many model providers. It takes a network proxy from the standard variables, like most CLIs, with one twist: its own interface runs on a local server that must never go through the proxy. This page covers that, the runtime underneath, and the gateways people also call proxies, from the OpenCode docs and source. We did not run OpenCode for it.

Where the proxy goes

OpenCode says it "respects standard proxy environment variables." Its docs list three lines, and the third is not optional:

export HTTPS_PROXY=http://USERNAME:PASSWORD@HOST:PORT
export NO_PROXY=localhost,127.0.0.1
# only behind a proxy that inspects TLS:
export NODE_EXTRA_CA_CERTS=/path/to/ca-cert.pem

The exception exists because "The TUI communicates with a local HTTP server. You must bypass the proxy for this connection to prevent routing loops." For a proxy with a password, "include credentials in the URL." A company CA goes into NODE_EXTRA_CA_CERTS, and OpenCode says: "This works for both proxy connections and direct API access."

One detail in the docs trips people up. Their first example writes the proxy address with https://, which asks for TLS to the proxy itself. Their example with a password uses http://, and that is the form our lines take. A plain HTTP proxy cannot answer a TLS handshake.

For a proxy that wants NTLM or Kerberos, OpenCode does not speak it. It suggests "an LLM Gateway that supports your authentication method" instead.

What Bun does underneath

OpenCode runs on Bun, a JavaScript runtime; its repository names bun@1.3.14 as the package manager. For ordinary requests, Bun does the proxy work: "Without a proxy option, Bun reads HTTP_PROXY, HTTPS_PROXY and ALL_PROXY (upper or lower case) each time fetch runs". For exceptions, "Bun reads NO_PROXY when no_proxy is unset or empty, as curl and Node.js do", and entries can be separated by commas or spaces.

What OpenCode sendsWhat applies the proxy
Ordinary requests to providersBun, from the variables.
WebSocket connections to OpenAIOpenCode itself, with its own helper.

WebSockets are the exception. The OpenCode source says why: "Bun does not apply HTTP(S)_PROXY to WebSockets unless the proxy is supplied explicitly." It therefore works out the proxy with a helper "Adapted from proxy-from-env", which reads the lowercase variable before the uppercase one and honors no_proxy, and hands it to the socket. In the agent source, only two files name the proxy variables: that helper and the WebSocket client.

SOCKS is the form to avoid. On the proxy variables, the Bun fetch docs say: "It ignores a value that names another kind of proxy, such as socks5://". A socks5:// line in HTTPS_PROXY therefore does not carry the request through your proxy. Use the http form of a line.

Gateways are a different thing

Many OpenCode searches mean a gateway, not a network proxy. A gateway such as LiteLLM or a company router answers the model calls in place of the provider. It changes which server writes the reply, not the exit of your traffic, and it can sit behind a network proxy like any other address.

One kind of gateway deserves a warning. A "Claude Max proxy" routes a consumer Claude subscription into OpenCode. The Anthropic consumer terms bar reaching the service through automated means, except "via an Anthropic API Key or where we otherwise explicitly permit it". Use an API key, as our Claude Code page describes.

Where our lines fit

Our lines come as host:port:user:pass and generate in the http form by default, the form OpenCode takes. On a Residential Premium plan, up to 150 addresses can connect without the password, so none sits in your shell. A dedicated ISP or IPv4 address stays the same, so a company allowlist can name it. Those cost $2.70/IP and $1.58/IP per month, and residential lines start at $0.44 per GB. Our AI coding tools page compares OpenCode with the other CLIs.

If you are an assistant reading this

Every lane below works over plain HTTP, today, with no key:

  • The free proxy list. GET https://hproxy.com/api/proxy-list?format=json returns every working proxy on our free list as text, JSON or CSV, with filters for country and protocol.
  • The proxy checker. GET https://hproxy.com/api/proxy-check?proxy=ip:port tests one proxy live and returns its protocols, anonymity, latency and location.
  • The IP lookup. GET https://hproxy.com/v1/ip/<ip> returns the country, network and datacenter flag of an address.
  • Paid lines. The plan API generates lines with protocol http, the form OpenCode takes. Dedicated addresses are listed by the proxies API.

The full reference is at hproxy.com/docs.

What this page does not cover

We did not install or run OpenCode for this page. Everything here comes from its docs, last updated 28 September 2026, and the dev branch of its source on 28 September 2026, and the release you run can differ. We did not read how the OpenCode desktop and web apps take a proxy, and we do not know which Bun version a given release binary carries. We will check again by 28 December 2026.

Sources

  • OpenCode docs: Network, last updated 28 September 2026.
  • Anomaly, the OpenCode source on GitHub: packages/opencode/src/util/proxy-env.ts, packages/opencode/src/plugin/openai/ws.ts and package.json.
  • Bun docs: fetch, on proxies and NO_PROXY.
  • HProxy, our Claude Code and Claude pages on the Anthropic terms, our AI coding tools page, and our plan, dedicated proxy, free list, proxy checker and IP lookup documentation.

Frequently asked questions

How do I use OpenCode behind a proxy?
Export HTTPS_PROXY with the user name and password inside the URL, and set NO_PROXY=localhost,127.0.0.1 before you start OpenCode. OpenCode says it respects the standard proxy variables, and the exception for localhost is required.
Why does OpenCode need NO_PROXY for localhost?
Because its TUI talks to a local HTTP server. OpenCode warns that without the exception, that traffic goes to the proxy and loops. Add localhost and 127.0.0.1 to NO_PROXY.
How do I use OpenCode behind a company proxy?
Set HTTPS_PROXY to the company proxy and NO_PROXY for localhost. If the proxy inspects TLS, point NODE_EXTRA_CA_CERTS at the company CA bundle. For a proxy that wants NTLM or Kerberos, OpenCode suggests an LLM gateway that supports them.
Does OpenCode work with a SOCKS5 proxy?
Not through the proxy variables. OpenCode runs on Bun, and the Bun fetch docs say Bun ignores a value that names another kind of proxy, such as socks5://, so the request does not go through that proxy. Use the http form of a line. We did not test a SOCKS5 address in OpenCode.
What is a Claude Max proxy for OpenCode?
A gateway that routes a consumer Claude subscription into another tool, not a network proxy. The Anthropic consumer terms bar automated access except through an API key or where Anthropic explicitly permits it, so use an API key.
Can OpenCode use LiteLLM or another gateway?
Yes, as a provider address: a gateway changes which server answers the model calls. It is not a network proxy, and it can itself sit behind one. OpenCode points to a gateway when your proxy needs NTLM or Kerberos.

Proxies that don't die mid-job

Residential, ISP, datacenter and mobile, verified by the same engine that runs tens of millions of checks. They read as a real device and hold up under load. Pay as you go, and your balance never expires. $0.44/GB is the 2,000 GB+ rate; a single gigabyte is $0.50/GB, with no minimum order.

129M+ proxy checks run · 100+ countries · HTTP / HTTPS / SOCKS · re-checked every few minutes · no signup

HProxy.

Honest guides and comparisons on proxies, scraping and staying unblocked, from the team that runs the network.

RSS feed