Browser Proxy Setup 2026: Chrome, Edge, Firefox and AI Browsers
A proxy that works in one browser may fail in another. Match authentication to the browser, then check extensions, DNS and the session that makes the request.
Before you configure anything
- Chrome and Edge commonly use operating-system proxy settings; Firefox also provides its own connection settings.
- Chromium cannot authenticate to a SOCKS5 proxy with a username and password. An HTTP endpoint can be the compatible choice.
- An AI-controlled cloud browser uses its own network. Configure that remote session rather than the browser showing its dashboard.
Decide which browser connection you are changing
Start with the browser that opens the target website. A desktop Chrome window, a Playwright browser and a Browserbase session are separate clients. One successful IP check does not establish that the other two use the same endpoint.
If you only need a single browser to use a proxy, avoid changing the router first. Use the browser's supported settings or a dedicated profile. Keep an ordinary direct profile available for checking whether a failure comes from the proxy or the destination.
Browser cookies and saved logins are independent of the network route. Changing the exit IP leaves those local records intact. For testing your own store, ads or location-specific content, define which variables should stay constant. Our quality-assurance proxy page covers the network side; browser profiles need their own handling.
Chrome, Edge and other Chromium browsers
On a standard Windows desktop setup, Chrome and Edge use system proxy configuration unless another supported control, such as a managed policy or extension, overrides it. Follow the Windows setup guide to enter an HTTP endpoint. On a Mac, use the active network service's proxy settings.
Chromium's own documentation distinguishes HTTP, HTTPS, SOCKS4 and SOCKS5. Its SOCKS5 implementation uses proxy-side destination resolution but does not support proxy authentication or UDP forwarding. A username/password SOCKS5 endpoint therefore needs a different compatible path.
Do not paste user:password@host into every proxy field and expect the browser to extract credentials. Use the application's authentication mechanism. If your provider supports HTTP on a different port, switch both protocol and port deliberately.
Extensions can choose a proxy configuration, but they cannot remove a limitation in the browser's underlying SOCKS implementation. If a tool claims to do so, identify whether it actually runs a separate local client or forwards through a different protocol.
For Opera or another Chromium derivative, check the vendor's own network features as well. A built-in VPN mode or another extension can change the effective route. Test with one controlling mechanism enabled at a time.
Firefox has its own connection controls
Open Firefox Settings and search for proxy. Mozilla's current connection-settings page shows version-dependent navigation, including a Proxy settings entry under Privacy and security in newer layouts. Searching the settings avoids relying on an old screenshot.
Open Configure proxy or Settings beside the matching network entry. Choose Manual proxy configuration, then enter the endpoint under HTTP Proxy or SOCKS Host as appropriate. For SOCKS, explicitly choose version 5 and inspect the proxy-DNS option. An HTTP proxy can also be selected for HTTPS website requests.
Review No Proxy For. Entries there bypass the chosen proxy. Mozilla also notes that the dialog identifies extensions controlling the connection. Disable that control for a clean manual test if an extension is overriding your change.
Authentication behavior depends on the selected protocol and client support. If a SOCKS5 endpoint needs credentials and the configuration cannot supply them, use a compatible extension or local client with documented support, or select the provider's HTTP endpoint. Do not infer success from the presence of a SOCKS Host field.
The existing Firefox walkthrough covers the single-browser workflow in more detail. Use this article to choose between browser families rather than maintaining several conflicting configurations.
What a proxy extension can and cannot do
A browser extension can make profile switching and domain rules more convenient. It also receives sensitive permissions related to your browsing. Download it through a publisher's official link and check the current maintainer, release notes and requested permissions.
The extension may provide a client interface only. If it asks for a server, port and credentials, you still need an upstream service. A browser-proxy extension does not normally route desktop apps or a remote browser controlled by an automation service.
Keep one proxy-controlling extension active during setup. A browser may allow only one effective configuration at a time, so importing the right endpoint into an inactive extension can leave requests on the old route. Clear the extension's own configuration only after recording any settings you need to restore.
For jobs involving private documents or AI conversations, treat browsing permissions as a data-access decision. A free extension's branding does not explain who operates the exit server or what information the extension can read. A client with a clear publisher and an endpoint you selected gives you a configuration you can inspect.
Safari and mobile browsers have a different scope
Safari on macOS uses the active network service's proxy configuration. Apple exposes separate HTTP, HTTPS and SOCKS settings there. Changing Wi-Fi settings does not necessarily configure an Ethernet connection or command-line program. Follow the Mac guide and verify each environment.
On iPhone or iPad, a Wi-Fi HTTP proxy is attached to a Wi-Fi network. For a client that can also operate on cellular and route supported app traffic, see Shadowrocket setup. The existing iPhone Wi-Fi walkthrough remains the narrower guide for that setting.
On Android, a Wi-Fi proxy setting can be ignored by apps that use their own networking. A local VPN-based proxy client has a different routing scope. The Android client guide explains how to test both Wi-Fi and mobile data without assuming that a VPN indicator proves every connection is proxied.
Configure a Playwright browser explicitly
Playwright supports proxy configuration at browser launch or per browser context. For an authenticated endpoint used with Chromium, an HTTP proxy is the straightforward documented option. Keep credentials in environment variables supplied by your runtime.
import { chromium } from 'playwright';
const { PROXY_SERVER, PROXY_USER, PROXY_PASSWORD } = process.env;
if (!PROXY_SERVER || !PROXY_USER || !PROXY_PASSWORD) {
throw new Error('Set the proxy endpoint and credentials first');
}
const browser = await chromium.launch({
proxy: {
server: PROXY_SERVER,
username: PROXY_USER,
password: PROXY_PASSWORD,
},
});
try {
const page = await browser.newPage();
await page.goto('https://api.ipify.org', { timeout: 30000 });
console.log(await page.locator('body').innerText());
} finally {
await browser.close();
}
Set PROXY_SERVER to an HTTP URL with the provider's host and port. The example verifies a browser request; it does not test the application outside the browser or the account workflow you eventually run.
Keep a session on a consistent endpoint while testing login-dependent behavior. If you need a new exit IP, finish the current task and start a fresh context where appropriate. Cookie isolation, proxy routing and rate control are separate responsibilities.
AI browsers, Browser Use and hosted sessions
Browser Use documents a browser proxy configuration with server, bypass and credential fields. Apply that configuration where its browser is created. A model API request made by the agent can follow another network path.
Browserbase configures proxies when creating a remote session and supports custom HTTP/HTTPS upstreams. If Stagehand or another controller connects to that browser, the browser's remote session configuration determines website egress. Local operating-system settings cannot change the cloud browser's exit IP.
MCP adds another possible execution environment. A local MCP server may launch a browser locally; a hosted server may fetch pages remotely. Inspect where the tool runs and which process opens the socket before setting HTTPS_PROXY or choosing a desktop routing rule.
For tool-specific wiring, use the existing Browser Use, Browserbase and MCP articles. Test the actual tool against an IP endpoint first. Avoid promising that one browser setting covers every AI tool or model provider.
Verify the route and the failure behavior
Check the browser's exit IP, then run a DNS test from the same profile. Inspect proxy exceptions, extension control and any active VPN. Record which layer owns the configuration so another operator can reproduce it.
If a page loads directly when the proxy stops, look for a direct fallback or bypass rule. That may be intentional for ordinary browsing, but it can invalidate a location-specific test. Decide whether failure should stop the task or permit another route.
WebRTC, downloads, service workers and app integrations deserve separate attention when they are part of your workflow. A single IP result is evidence about that request. It is not a full browser privacy audit. Keep the test proportional to what you are using and repeat it after a client or browser update.
Sources and review scope
This guide was checked against the documentation below on October 11, 2026. Software behavior depends on the installed version, operating system and proxy service. Configuration examples are illustrative; this is a documentation review, not a benchmark of every client.
Frequently asked questions
Continue with your device
Protocol basics, operating-system setup and client choices in one series.
Related workflows
Follow the existing guide for a single Firefox profile.
Keep the model connection separate from browser egress.
Configure the proxy on the hosted browser.
Use repeatable locations for permitted search checks.