A Mac has one proxy page that Safari, Chrome and most apps follow, a Terminal command that sets the same thing, and a separate world of command-line tools that ignore both and read environment variables instead. This guide covers all three, and which apps quietly skip the system proxy. Menu names are from Apple’s current Mac User Guide, checked in September 2026.
How to set a proxy on a Mac
Short answer: Apple menu → System Settings → Network, click the network you use, click Details, then Proxies. Step by step:
- Choose Apple menu → System Settings and click Network in the sidebar.
- Click the network service you are connected through, such as Wi-Fi, then Details next to the network name.
- Click Proxies in the list on the left. You may need to scroll down.
- Turn on Web proxy (HTTP). Enter the proxy IP from your dashboard as the server, and its port.
- Turn on Secure web proxy (HTTPS) and enter the same IP and port. This one covers
https://sites, which is nearly all of them. It does not mean the proxy has to speak HTTPS: it is still the same HTTP proxy, and your HTTPS traffic passes through it in an encrypted tunnel. - If you use a username and password, turn on Proxy server requires password under each and fill them in.
- Click OK.
The settings belong to that network service. Set them on Wi-Fi, plug in an Ethernet cable, and you are off the proxy. Repeat the steps for each service you use.
The other switches on the Proxies pane
- SOCKS proxy: for a SOCKS5 proxy. Use the host and port your dashboard lists for SOCKS5 on your order, if it lists them; do not guess a port. Not every app that follows the HTTP settings follows this one.
- Auto proxy discovery and Automatic proxy configuration: for office networks, or for a PAC file you point at with a URL. Leave them off when you type a proxy in by hand.
- Exclude simple hostnames: skip the proxy for names without a dot, such as
http://nas. Worth turning on. - Bypass proxy settings for these hosts & domains: the sites that go direct, separated by commas. The defaults,
*.localand169.254/16, keep local devices off the proxy; add to them rather than replacing them.
Who uses the password you saved
The Proxy server requires password switch stores the password on the Mac, but it is up to each app whether to use it. Safari picks up the system settings. Chrome follows the system address but ignores the stored password and shows its own sign-in box instead; type the details there and it remembers them until you quit. Other apps may do either, or just fail with a network error. If one app refuses to cooperate, an IP allowlist ends the argument: every ProxyMonkey line supports one, and with your public IP on it, no app needs a password at all. It holds only while that IP stays the same.
Set a proxy from Terminal with networksetup
Everything on that pane can be scripted with networksetup, which comes with macOS. First, the exact name of the network service:
networksetup -listallnetworkservicesNames with spaces or dashes are safest in quotes, as in "Wi-Fi" or "USB 10/100/1000 LAN". Then set the HTTP and HTTPS proxies. The fourth argument turns password authentication on or off:
networksetup -setwebproxy "Wi-Fi" IP PORT on USER PASS
networksetup -setsecurewebproxy "Wi-Fi" IP PORT on USER PASS
networksetup -setproxybypassdomains "Wi-Fi" "*.local" "169.254/16" "*.example.com"For a proxy with no password, such as one using an IP allowlist, leave off the last three arguments. For SOCKS it is -setsocksfirewallproxy, with the same arguments. Changing network settings needs an admin account; if a command refuses, run it again with sudo in front.
To check what is set, or switch it off again:
networksetup -getwebproxy "Wi-Fi"
networksetup -getsecurewebproxy "Wi-Fi"
networksetup -setwebproxystate "Wi-Fi" off
networksetup -setsecurewebproxystate "Wi-Fi" off-setproxybypassdomains replaces the whole list, so include the defaults you want to keep; pass Empty to clear it. And typing a password on the command line leaves it in your shell history. For a script you will share, use the allowlist.
Proxy for Terminal: environment variables
curl, git, pip, brew and most command-line tools do not read the system settings at all. They read environment variables. For the current Terminal window:
export http_proxy="http://USER:PASS@IP:PORT"
export https_proxy="http://USER:PASS@IP:PORT"
export no_proxy="localhost,127.0.0.1"Two details trip people up. Use the lower-case names: curl ignores an upper-case HTTP_PROXY on purpose, while most other tools read both. And https_proxy starts with http://, because it names how to reach the proxy, not the site. To keep the variables for every new window, add the same lines to ~/.zshrc, knowing the password then sits in a plain text file.
Which Mac apps ignore the system proxy
- Safari and Chrome: follow System Settings. Chrome has no proxy fields of its own.
- Firefox: follows the system by default, but has its own proxy settings, per Firefox profile, which override it.
- curl, git, Homebrew and most CLI tools: environment variables only.
- Python:
requestsreads the environment variables first and falls back to the system address if there are none, but never gets the password from it. With a password-protected proxy, set the variables or the proxy in code. - Node.js: ignores the system settings, and whether it reads the variables depends on the library, so set it in code.
- Video calls, games and anything over UDP: not through an HTTP proxy at all.
Check your exit IP
To test the proxy on its own, before any settings get involved:
curl -x http://IP:PORT --proxy-user USER:PASS https://httpbin.org/ipThe origin in the reply should be your proxy’s IP. Then open https://httpbin.org/ip in Safari to check the System Settings proxy, and run plain curl https://httpbin.org/ip to check the variables. curl never reads System Settings, so it cannot test them. More options are on the curl setup page.
Mac proxy not working? Common fixes
A password prompt keeps coming back
The proxy is rejecting the credentials, or getting none. Retype them in both the HTTP and HTTPS sections; each has its own. Look in Keychain Access for an old saved entry naming the proxy IP, and delete it. The 407 Proxy Authentication Required page covers the rest.
Only some sites use the proxy
Almost always the HTTPS half is missing. With only Web proxy (HTTP) on, http:// pages go through the proxy and every https:// page goes direct.
Nothing loads after turning it on
The Mac cannot reach the proxy: a typo in the IP or port, or an order that has ended. Test with the curl -x line above, then the connection refused guide. A VPN app or a configuration profile from work can also override the pane without telling you.
Which proxy to use for a Mac
A whole-machine proxy wants one address that stays put. A static ISP proxy or datacenter proxy gives you that. Rotating residential gives a new exit on every new connection, and a Mac opens connections all the time, so logins break; if you need residential, turn on a sticky session in your dashboard first.
Setting up a PC too? The Windows proxy settings guide is the same walk-through for Windows 11. And if you only want a few sites through the proxy, a browser extension beats a system setting: see the FoxyProxy setup guide.
Top-ups start at $5.
One shared datacenter IP for 30 days is $2.10. A single gigabyte of residential is $5.50. The balance never expires.