Free tool
Proxy setup generator one proxy line, the exact settings for each place
Paste the proxy your provider gave you and get the boxes to fill on Windows, a Mac, Android or an iPhone, and the lines for netsh winhttp, networksetup, Linux, Firefox, Chrome, curl and Python. The password is written the way each place expects it, and the whole thing runs in your browser: it never leaves the tab.
Protocol
Example, until you paste yours: host:port:user:passhost 203.0.113.10port 8080user alicepassword s3cret
Where it goes
Windows 11 Settings
- 1Open Settings, then Network & internet, then Proxy.
- 2Under Manual proxy setup, select Set up next to Use a proxy server. Once a proxy is saved, the button reads Edit.
- 3Switch Use a proxy server on.
- 4Proxy IP address
203.0.113.10 - 5Port
8080 - 6Select Save.
On Windows 10 the path is Settings, Network and Internet, Proxy: under Manual proxy setup turn on Use a proxy server, and the boxes are Address and Port.
To turn it off: Edit next to Use a proxy server, switch it off and Save.
Windows services: netsh
netsh winhttp set advproxy setting-scope=machine settings={\"Proxy\":\"203.0.113.10:8080\",\"ProxyBypass\":\"\",\"AutoconfigUrl\":\"\",\"AutoDetect\":false}
netsh winhttp show advproxy
netsh winhttp set proxy proxy-server="203.0.113.10:8080"
netsh winhttp show proxy
This is the proxy Windows services use, Windows Update among them, not your browser's. Microsoft marks set proxy as deprecated in favour of set advproxy. To undo either: netsh winhttp reset proxy.
Programs started from one PowerShell window
$env:HTTP_PROXY = 'http://alice:s3cret@203.0.113.10:8080'
$env:HTTPS_PROXY = 'http://alice:s3cret@203.0.113.10:8080'
$env:NO_PROXY = 'localhost,127.0.0.1,::1'
curl.exe -s https://www.cloudflare.com/cdn-cgi/trace | Select-String '^ip='
curl.exe, Python, pip and git read these. They last until the window closes, and the ip= line should show the proxy's address.
The whole story, with the errors and the fixes: The Windows proxy guide →
How it works
Three steps, none of them on a server
Nothing to install and nothing to sign up for. Paste, pick a place, copy.
01
Paste the line you were given
host:port, host:port:user:pass, user:pass@host:port or a full socks5:// address. The same reader as our proxy formatter takes it apart and shows you what it read, password included, so you can see it got it right.
02
Pick where it goes
Windows, a Mac, Linux, Android, an iPhone, Firefox, Chrome, curl, Python, a PAC file or a local relay. Each one gets its own boxes to fill or lines to run.
03
Copy what you need
Every value and every block has its own copy button. Where a place cannot take something, a login on Windows or SOCKS5 on an iPhone, the page says so and shows the way round it.
What each place takes
Ten places, ten different rules
Which proxy types each one accepts, where the login goes, and how it wants the list of sites that skip the proxy. The generator follows this table; the guides behind it cite the makers' own documentation.
| Place | Proxy types | Login | Sites that skip it |
|---|---|---|---|
| Windows Settings | HTTP | No field: Chrome and Edge ask | Semicolons |
| netsh winhttp | HTTP | None | Semicolons |
| macOS | HTTP, HTTPS, SOCKS | In Settings and networksetup | Commas |
| Linux shell, apt, dnf | HTTP, SOCKS5 in the shell and dnf | Inside the URL, encoded; dnf in its own lines | no_proxy, commas |
| Android Wi-Fi | HTTP | No field: Chrome asks | Commas |
| iPhone Wi-Fi | HTTP | The Authentication switch | None: use a PAC file |
| Firefox | HTTP, SOCKS5 | Asked in a window, HTTP only | Commas, .domain |
| Chrome command line | HTTP, SOCKS5 | None | Semicolons |
| curl, Python requests | HTTP, SOCKS5 | Inside the URL, encoded | no_proxy |
| PAC file | HTTP, SOCKS5 | None | Rules you write |
Why it is not trivial
The hard part is the password, not the address
Typing a host and a port into a box takes a second. Writing the password the way each place reads it is where setups fail, and they fail with a 407 that explains nothing.
One password, several spellings
The same password goes into a URL percent-encoded, into a Mac command inside single quotes, into squid.conf with every % doubled, and into Windows not at all. p@ss is p%40ss in the curl line and stays p@ss on the Mac. One wrong character and the proxy answers 407 with no hint why.
Each place says what it cannot do
Windows and Android have no field for a proxy login, the iPhone has no list of exceptions, and Chrome takes no login for SOCKS5 at all. Instead of writing settings that cannot work, the page names the limit and the fix: a sign-in window, an address allowlist, a PAC file or a relay.
Every line has a source
The commands come from the makers' own documentation: Microsoft's netsh reference, Apple's networksetup manual, Android's settings, Firefox's preference names, Chromium's flags, and the curl, requests, Squid and gost manuals. Each place links to our full guide for it.
Nothing is sent anywhere
The input to this tool is a proxy with its password. The line is read and every setting is written by JavaScript in your browser, and the page makes no request with what you type. Disconnect from the internet after the page loads and it still works.
Questions
Proxy setup generator FAQ
The netsh, Mac and password questions people ask before they set a proxy up, answered against what the generator actually writes.
What does the proxy setup generator do?
It turns one proxy line into the exact settings for the place you want to use it: the boxes to fill on Windows, macOS, Android or an iPhone, and the commands or files for netsh, networksetup, a Linux shell, apt, dnf, Firefox, Chrome, curl, Python, a PAC file or a local relay. The password is written the way each place expects it.
How do I set a proxy with netsh winhttp set proxy?
Open Command Prompt as administrator and run netsh winhttp set proxy proxy-server="203.0.113.10:8080", adding bypass-list="*.example.com" for sites that should skip it. Microsoft marks set proxy as deprecated in favour of netsh winhttp set advproxy, which takes the same values as JSON, so the generator writes both. netsh winhttp show advproxy shows the result and netsh winhttp reset proxy removes it. Neither takes a user name or password, and SOCKS5 is not supported.
Does netsh winhttp change my browser's proxy?
No. netsh sets the WinHTTP proxy, which Windows services use, Windows Update among them. Chrome and Edge read the proxy in Settings, Network & internet, Proxy, which belongs to the signed-in user. To change what the browser uses, fill in that page; the generator gives you both.
How do I set a proxy on a Mac from Terminal?
With networksetup. networksetup -setwebproxy "Wi-Fi" 203.0.113.10 8080 sets the web proxy for the Wi-Fi service, -setsecurewebproxy does the same for HTTPS, and on with a user name and a password at the end turns the login on. networksetup -listallnetworkservices lists the service names, and scutil --proxy shows what the Mac now uses.
How do I write a proxy password with special characters?
It depends on where it goes. Inside a URL, which is how curl, Python requests and the http_proxy variable take it, special characters are percent-encoded: @ becomes %40, : becomes %3A, # becomes %23 and / becomes %2F. Typed into a settings screen, or handed to networksetup as an argument of its own, it stays exactly as issued. The generator writes each form, so p@ss:word appears as p%40ss%3Aword in the curl line and as p@ss:word on the Mac.
Why is there no password box on Windows or Android?
Neither has a field for a proxy login. Chrome and Edge ask for the user name and password in a sign-in window when the proxy wants one. A program that cannot ask needs your provider to allow your IP address instead, or a small relay on your own computer that adds the login, which the generator also writes.
Does it work with SOCKS5?
Where the place supports it: macOS, the Linux shell and dnf, Firefox, Chrome's command line, curl, Python requests, PAC files and the relay. Windows' proxy settings, netsh, Android's Wi-Fi proxy and the iPhone's take HTTP only, and the generator says so instead of writing settings that cannot work.
Is my proxy password sent to your server?
No. The line is read and every setting is written by JavaScript running in your browser, and the page makes no request with what you type. You can disconnect from the internet after the page loads and it keeps working.
Can I use it with proxies from any provider?
Yes. It reads the line shapes every provider exports, with the same reader as our proxy formatter, and it never checks where a proxy came from or whether you have an account.
How do I check that the proxy took?
Run the curl line from the generator: the ip= line it prints should show the proxy's address, not yours. In a browser, our Proxy IP Checker shows the address that actually reached the server.
After the setup
A saved setting is not a working proxy. Check it next.
The settings can be exactly right and the traffic can still go around the proxy. Two free checks tell you which.
The upgrade
Residential proxies
$0.44per GB, and the balance never expires
Clean pools with city-level targeting and sticky sessions, running on the same network that just probed your list. You stop re-checking a file every morning, because the addresses are not shared out from under you.
Elsewhere on HProxy
Proxy IP Checker
The address that actually reached our server. If it is still your own, the traffic never entered the proxy.
Proxy Leak Test
WebRTC, IPv6 and forwarding headers, each with its own verdict, for when the proxy works and sites still recognise you.
PAC File Tester
Paste a PAC file and see where it sends any address, run in your browser.
Proxy Formatter
A whole list in another shape, for the programs that take many proxies at once.