Scripts are the easy case: you put the proxy in a URL and move on. Browsers are fussier. Chrome borrows your operating system’s settings, Firefox keeps its own, and neither will take a SOCKS5 password. Here is how to use a proxy in Chrome and Firefox with a username and password, how to keep it to one window instead of your whole computer, and how to check it is really working.
How to use a proxy in Chrome
Chrome has no proxy fields of its own. It uses your computer’s proxy settings, and when the proxy asks for a password, Chrome shows a sign-in box. So you either change the system settings, which affects every app on the machine, or launch Chrome with a flag, which affects only that window.
The first route is quick to set up. The second is usually what you actually want.
Route 1: the system settings
In Chrome, open Settings → System → Open your computer’s proxy settings. That button takes you to:
- Windows 11: Settings → Network & internet → Proxy. Next to Use a proxy server, click Set up, turn it on, enter the proxy IP and port, and save.
- macOS: System Settings → Network → your network → Details → Proxies. Turn on Secure web proxy (HTTPS) and Web proxy (HTTP), and enter the same IP and port in both.
Windows has no password field here. macOS has a Proxy server requires password switch, but Chrome ignores credentials stored in system settings anyway. Either way, the first page you open brings up Chrome’s own sign-in box for the proxy. Type the username and password from your dashboard, and Chrome remembers them until you quit it. The Windows and macOS proxy settings guides cover those screens in full.
The catch: this is now the proxy for your whole computer. Edge, Safari, your mail client, background updaters, anything that honours the system setting goes through it, and on a proxy billed by the gigabyte that is money leaking out of apps you forgot were running.
Chrome proxy with username and password, in one window only
Chrome takes a --proxy-server flag that overrides the system settings for that process. The trick that makes it work is a second flag, --user-data-dir, pointing at a separate profile folder. Without it, if Chrome is already open, your command just adds a window to the running browser, and the flag is ignored.
On macOS:
open -na "Google Chrome" --args \
--user-data-dir="$HOME/chrome-proxy" \
--proxy-server="http://IP:PORT"On Windows, in Command Prompt:
"C:\Program Files\Google\Chrome\Application\chrome.exe" --user-data-dir="%LOCALAPPDATA%\chrome-proxy" --proxy-server="http://IP:PORT"On Linux:
google-chrome --user-data-dir="$HOME/chrome-proxy" --proxy-server="http://IP:PORT"Your normal Chrome carries on without a proxy. The new window has its own cookies, logins and extensions, and it keeps them between runs, so it works like a separate work profile, with your proxied browsing kept apart from your personal browsing. Put the command in a shortcut and you have a one-click proxied browser. Once you want one of these per client, each with its own IP, a multi-profile browser does the bookkeeping, and the antidetect browser proxy guide covers how to set one up.
Do not put the username and password in the flag. Chrome does not read credentials from the proxy string; it will still show the sign-in box, which is what you want.
Firefox proxy settings, step by step
Firefox keeps its own proxy settings, separate from the system and separate for each Firefox profile. That makes it the easier browser for this job.
- Open Settings and type
proxyinto the search box. - Click the button that comes up: Configure proxy in current versions, Settings… under Network Settings in older ones.
- Choose Manual proxy configuration.
- In HTTP Proxy, enter the IP, and the port in Port. Tick Also use this proxy for HTTPS.
- Leave the SOCKS fields empty and click OK.
Load any page and Firefox asks for the proxy’s username and password. It can save them, and the Do not prompt for authentication if password is saved box in the same dialog stops it asking each time.
For SOCKS5 you would fill in SOCKS Host, pick SOCKS v5 and keep Proxy DNS when using SOCKS v5 ticked, so the proxy resolves hostnames instead of your own DNS. Current Firefox ticks it by default. But see the next section before you do.
Since the settings belong to the profile, the Firefox version of the one-window trick is a second profile. Open about:profiles, create one, launch it, and set the proxy there only.
Why SOCKS5 with a password does not work in browsers
Chrome’s network stack implements no authentication for SOCKS5 proxies. There is no prompt, no flag and no setting; a SOCKS5 proxy that wants a password simply fails. Firefox’s settings have no username or password field for SOCKS either. The protocol supports it, the browsers do not ask. The SOCKS5 vs HTTP proxy explainer has the full comparison, but for browsers there are three ways out:
- Use HTTP instead. Every line we sell speaks HTTP, HTTPS and SOCKS5, and for browsing there is nothing SOCKS5 gives you that HTTP does not. This is the answer nine times out of ten.
- Allowlist your IP. Every line supports an IP allowlist as well as a username and password. With your own IP on it, the proxy stops asking for a password, and SOCKS5 works in both browsers. It only holds while your home IP stays the same.
- Use an extension, in Firefox. Firefox’s extension API can hand a SOCKS5 username and password to the browser. Chrome’s cannot, because the network stack underneath has nowhere to put them.
Extensions are also how you send some sites through a proxy and the rest direct. The SwitchyOmega setup guide does that step by step, with rules per site and fixes for the password prompt that keeps coming back, and the FoxyProxy setup guide does the same for Firefox. Without an extension, the PAC file generator writes per-site rules as a PAC file that Firefox or the system proxy settings can load.
Check it worked: your IP and WebRTC leaks
Open https://httpbin.org/ip in the proxied window. It prints the address the site sees. That should be your proxy’s IP, not yours. If it is yours, the browser is not using the proxy: check you are in the right window or profile, and that no extension has taken over the proxy settings (Chrome says so under Settings → System).
You do not need a separate DNS leak test for an HTTP proxy. The browser hands the hostname to the proxy, and the proxy does the lookup, so your own DNS resolver never hears about the sites you visit through it. With SOCKS5, Chrome also always leaves the lookup to the proxy; in Firefox, that is what the Proxy DNS checkbox is for.
If the password prompt keeps coming back, the proxy is rejecting the credentials. That is a 407, and the 407 Proxy Authentication Required fixes cover it.
Then WebRTC, the browser feature behind video calls. It can send UDP straight out of your connection, skipping an HTTP proxy, and a page can use it to learn your real public IP even when the page itself came through the proxy. To close it:
- Firefox: in
about:config, setmedia.peerconnection.ice.proxy_only_if_behind_proxytotrue. It isfalseby default. - Chrome: there is no switch in Settings. Add
--force-webrtc-ip-handling-policy=disable_non_proxied_udpto the launch command from earlier, or use an extension that sets the same policy.
Search for a “WebRTC leak test” page and run it in the proxied window before and after. If your home IP shows up in the before and not in the after, you are done.
Which proxy to put behind a browser
A browser session wants one address that stays put. Log in from one IP and click a link from another, and plenty of sites will log you out or ask you to prove who you are.
- ISP proxies are the usual answer. A static address hosted in a data centre but registered to a consumer ISP, in a country you pick at checkout. One dedicated ISP IP for 30 days is $3.20, and it stays yours for the term.
- Datacenter, if the sites do not mind. Same idea, same browser setup; a dedicated datacenter IP is $3.20 for 30 days. Some sites block hosting ranges, and the four-question proxy type guide tells you whether yours do.
- Not plain rotating residential. Our residential gateway,
resi.proxymonkey.io:8000, gives a new exit on every new connection. A browser reuses connections and opens new ones when it sees fit, so when your address changes is unpredictable from one page load to the next, and a login may not survive the next click. If you need residential in a browser, turn on sticky sessions in your dashboard first; rotating vs sticky explains the trade.
Whatever you pick, keep proxied browsing in its own browser profile, apart from your personal browsing, and sign in to each account you hold from the same profile and IP every time. That one habit does more for staying logged in than any proxy setting.
Top-ups start at $5.
One shared datacenter IP for 30 days is $2.10. A single gigabyte of residential is $5.50. The balance never expires.