Guide · 6 min read

Using a proxy in Postman: settings, authentication and checking your exit IP

Send Postman requests through a password-protected proxy, choose system or custom proxy settings, check the exit IP, and fix the usual proxy errors.

Postman sends requests from your own connection by default, which is fine until you need to see what an API does for a caller somewhere else: another country, a different network, an address that is not on your office allowlist. A Postman proxy fixes that in one settings tab. This guide covers the settings, the username and password, how to prove the request really left through the proxy, and what the usual errors mean.

Menu names and options below are from Postman’s own documentation and the desktop app, checked in September 2026.

How to set a proxy in Postman

Short answer: in the Postman desktop app, open Settings, go to the Proxy tab, turn on Use custom proxy configuration, enter the proxy host and port, turn on Proxy auth with your username and password, and send a request to https://httpbin.org/ip to check the address it reports.

The Proxy tab has two switches under Proxy configurations for sending requests, and it helps to know which one you want before you touch either:

  • Use system proxy sends requests through whatever proxy your operating system is set to. Pick this if the proxy is already configured in Windows or macOS and you want Postman to follow it.
  • Use custom proxy configuration gives Postman its own proxy, independent of the rest of the machine. This is the one you want for a paid proxy you only use for testing.

If both are on, Postman’s documentation says the custom proxy wins.

Postman proxy settings, step by step

  1. Click the settings icon in the header, then Settings, then the Proxy tab.
  2. Turn on Use custom proxy configuration.
  3. Under Use proxy for, leave both HTTP and HTTPS ticked. Most APIs are https://, and unticking HTTPS is the classic way to set up a proxy that never gets used.
  4. Under Proxy server, pick HTTP in the protocol dropdown. Enter the host in the first box and the port in the second, with no http:// in front. For the rotating residential gateway that is resi.proxymonkey.io and port 8000; for a static ISP or datacenter proxy, the IP and port from your dashboard.
  5. Use Proxy bypass for hosts that must not go through the proxy, as a comma-separated list. localhost and your internal API hosts belong here.

HTTP or SOCKS5? Postman’s dropdown also lists SOCKS5, SOCKS5H, SOCKS4 and SOCKS4A, and SOCKS5 works too: our proxies speak it as well as HTTP. Pick SOCKS5H so the proxy resolves hostnames. Postman’s docs say only HTTP and HTTPS requests go through a SOCKS proxy, so no WebSocket or gRPC that way. HTTP is the simpler default, and it still carries your https:// requests through an encrypted tunnel it cannot read. The SOCKS5 vs HTTP proxy guide has the longer version. Whichever you pick, use the details your dashboard shows.

Postman proxy authentication: username and password

Still in the custom proxy section, turn on Proxy auth and fill in Username and Password from your dashboard. Paste them rather than typing, and check for a trailing space; a stray space is a wrong password as far as the proxy is concerned.

There is a second, separate authentication box at the top of the tab, Default proxy configuration with This proxy requires authentication. That one is for the proxy your operating system is set to, which Postman uses by default for requests and for reaching its own online services, and it needs Save and Restart Postman. For a proxy you only want API requests to use, leave it alone and use the custom section.

Using the system proxy and HTTP_PROXY environment variables

With Use system proxy on, a second toggle lets Postman read the HTTP_PROXY, HTTPS_PROXY and NO_PROXY environment variables. Postman’s documentation suggests starting the app from a small script that sets them, with the credentials in the URL:

HTTP_PROXY=http://USER:[email protected]:8000 \
HTTPS_PROXY=http://USER:[email protected]:8000 \
NO_PROXY=localhost,127.0.0.1 \
/path/to/postman

The flip side catches people out. Postman’s proxy settings page warns that if these variables are set on your system, Postman uses them and ignores the proxy settings in the app. If your custom proxy “does nothing”, run env | grep -i proxy in a terminal first.

Does the Postman web app use a proxy?

Postman’s docs are explicit on one point: you cannot configure the default proxy in the web app. The web app sends requests through an agent you pick in the footer. The Desktop Agent is a small app that routes requests through your own machine and network; the Cloud Agent sends them from Postman’s servers.

The agent documentation does not say how proxy settings apply to each agent, and we would rather not guess. What we can say: a request sent by the Cloud Agent leaves from Postman’s cloud, not from your proxy. If the exit address matters, use the desktop app and check it with the request below.

Check your exit IP in Postman

Create a GET request to this address and send it:

https://httpbin.org/ip

The origin in the response should be the proxy’s address, not yours. Turn the custom proxy off, send again, and it should change to your own. To log it on every send, add this under the request’s Scripts tab, in Post-response:

console.log("exit IP:", pm.response.json().origin);

Then open the Console from the Postman footer (Ctrl+Alt+C, or ⌘+Option+C on a Mac). Postman logs every request there, including the proxy configuration it used, which is the fastest way to see whether a request went through the proxy at all.

On the residential gateway, a new connection gets a new address. Postman may reuse a connection between sends, so two clicks in a row can show the same IP. Running the request several times from the Collection Runner is worth a try, though Postman does not document whether each iteration opens a new connection. If you need the same address for a whole login flow, use a sticky session from the dashboard; the rotating vs sticky guide explains when each fits. To test an API from one particular country, use a static ISP proxy: you pick its country at checkout, while residential does not let you choose.

Postman proxy errors and fixes

407 Proxy Authentication Required

The proxy got no credentials, or the wrong ones. On an http:// URL you see a 407 status in the response. On an https:// URL the proxy refuses the tunnel before the API is ever reached, so Postman reports an error instead of a response, often worded like tunneling socket could not be established, statusCode=407. Check that Proxy auth is on in the custom section, not the default one, and re-paste the password. The 407 Proxy Authentication Required page covers the rest.

Could not get a response, or a tunneling socket error

When Postman cannot connect at all, the response pane shows an error panel instead of a response. With a proxy in the picture, the common causes are a mistyped host or port, a protocol set to SOCKS for an HTTP proxy, an order that has ended, or a network that blocks the port. It is the same failure Chrome calls ERR_TUNNEL_CONNECTION_FAILED. Take Postman out of the question with curl; the curl setup page has the variations.

curl -x http://USER:[email protected]:8000 https://httpbin.org/ip

If curl works and Postman does not, look for leftover HTTP_PROXY variables or a bypass entry that matches the API’s host.

SSL errors behind a corporate proxy

An HTTP proxy like ours tunnels HTTPS and never touches the certificate. Errors such as self signed certificate in certificate chain usually mean a company proxy on your network is inspecting traffic and presenting its own certificate. Postman’s docs offer turning off SSL certificate verification in settings; the better fix is adding your company’s CA certificate under Settings → Certificates, so you keep checking everyone else’s. The SSL certificate errors page goes through the variants.

Newman: the same proxy from the command line

Newman, Postman’s collection runner for the terminal and CI, has no proxy flag. Its README says it reads HTTP_PROXY, HTTPS_PROXY and NO_PROXY (and their lowercase forms) instead:

HTTPS_PROXY=http://USER:PASS@IP:PORT \
HTTP_PROXY=http://USER:PASS@IP:PORT \
newman run my-collection.json

For residential, use http://USER:[email protected]:8000 as both values instead. A static address is the calmer choice for a test suite: when a test fails, you know the IP did not change underneath it.

Building the same thing into an automation instead of a test? The n8n proxy guide covers the HTTP Request node. And if you get stuck, post the Console output, password removed, in Discord.

Try it while you read

Top-ups start at $5.

One shared datacenter IP for 30 days is $2.10. A single gigabyte of residential is $5.50. The balance never expires.

Published

Filed under

Found a mistake? Tell us in Discord and we will fix the post.

The community layer

Stuck halfway through?

Paste the error in Discord. Someone has hit it before and the answer is usually one message long.

Join the Discord

4,200+monkeys in the Discord

  • Help from humans

    Post your error, get an answer. Usually in minutes, usually from someone who has hit the same wall.

  • A status bot that tells on us

    Pool health, incidents and maintenance posted automatically. Including the bad days.

  • Deals and free traffic

    Bonus GB drops, early access to new pools, and the occasional giveaway for a good bug report.

Join the Discord4,200+ monkeys, free to lurk