All systems operationalโ€ขIP pool status
Coronium Mobile Proxies
Proxy software guides

Mac Proxy Setup 2026: macOS Settings, Terminal and App Routing

A Mac can have one proxy for Safari, another for a terminal command and another inside a browser agent. Configure the network layer that performs the request.

Coronium Technical TeamSources checked 10 min read

Before you configure anything

  • macOS proxy settings belong to a network service such as Wi-Fi or Ethernet.
  • A successful Safari test does not verify Terminal, Docker or an AI tool's separate network client.
  • Use per-command proxy options first. Move to per-app or TUN routing only when the workflow needs it.

Set a proxy on the active macOS connection

Apple's proxy-settings documentation describes controls for the selected network service. On current macOS layouts, open System Settings, choose Network, select the active service, then open Details and Proxies. A Wi-Fi connection can also expose Details from its own settings panel.

Enable the protocol supplied by your provider: Web Proxy (HTTP), Secure Web Proxy (HTTPS) or SOCKS Proxy. Enter the host and port separately and use the credential fields where required. Review bypass entries before saving. Configure only the choices needed for your endpoint rather than turning on every protocol.

Apple's label for secure web traffic is not sufficient to establish that the client-to-proxy connection itself uses TLS. Confirm the endpoint scheme and application behavior if you need encryption between the client and proxy. The SOCKS5 guide separates that issue from HTTPS website encryption.

Open Safari and check the browser's exit IP. If you switch to Ethernet, verify the active service's settings again. To undo the test, return to that service and disable the proxy entries you added, preserving any managed or previously required configuration.

Safari, Chrome and Firefox can behave differently

Safari commonly uses macOS networking settings. Chrome also supports system configuration, but a browser policy or extension can override the expected route. Firefox exposes its own proxy configuration, which can either use system settings or specify a different endpoint.

If a proxy works in Safari but fails in Chrome, compare the selected protocol and authentication support. A shared operating-system dialog does not guarantee identical browser implementations. Use a compatible HTTP endpoint for authenticated Chromium browsing or a documented local client arrangement.

Keep one browser as a control during initial setup. Test a known HTTPS page and an IP endpoint before opening a logged-in workflow. Remove a stale extension rule if it is overriding the system setting, then retry the same request.

The browser guide covers the browser-specific choices, while the Firefox walkthrough stays focused on that application's controls.

Test a proxy directly from Terminal

Command-line tools do not all inherit macOS settings in the same way. Use an explicit option when the tool offers one; it makes the test easier to reproduce. These curl commands use a documentation address. Replace it with the endpoint supplied by your provider.

# SOCKS5 with destination DNS handled by the proxy
curl --fail --show-error --connect-timeout 10 --max-time 30 \
  --proxy socks5h://192.0.2.10:1080 \
  --proxy-user proxy-user https://api.ipify.org

# HTTP proxy, tunneling an HTTPS destination
curl --fail --show-error --connect-timeout 10 --max-time 30 \
  --proxy http://192.0.2.10:8080 \
  --proxy-user proxy-user https://api.ipify.org

Curl prompts for a password when only the username is supplied. This avoids storing the password literally in the command line you typed. Automated jobs should obtain credentials from their runtime's secret mechanism and avoid printing them in logs.

The curl documentation distinguishes an explicit proxy from environment variables and bypass settings. If a request unexpectedly goes direct, inspect the effective configuration, including NO_PROXY or no_proxy. An inherited exception can invalidate a test even when the endpoint is correct.

Use a command-local setting for the first experiment. Do not immediately add a proxy export to your shell startup file: every subsequent terminal session may inherit it, including unrelated package installs or deployment commands.

A local SSH SOCKS tunnel is a different exit network

If you control an SSH server, OpenSSH can create a local SOCKS listener with dynamic forwarding. OpenSSH documents the -D option. For example:

ssh -N -D 127.0.0.1:1080 user@your-ssh-server

This binds the listener to loopback and forwards through the SSH server. Configure a compatible app to use 127.0.0.1 and port 1080, then verify its exit address. The SSH server's network becomes the exit; this does not turn a datacenter server into a mobile proxy.

The listener disappears when the SSH process or connection ends. If the browser still points at it, browsing can fail until you restart the tunnel or remove the setting. Keep a terminal window or service status available so that this failure is visible.

A local listener bound to every interface can become accessible to other devices. Bind only where needed and use explicit access controls if you intentionally share it. A tunnel that works on your own laptop does not need to accept connections from the LAN.

Choose per-app routing or a TUN client

Use a per-app client when a desktop application has no suitable native proxy setting. Proxifier's Mac documentation is separate from its Windows documentation; check the edition and current OS compatibility instead of copying Windows menu paths blindly.

Clash Verge Rev supports macOS and offers system-proxy and TUN modes. v2rayN also lists macOS support. These can manage rule-based configurations, but the selected core and mode determine routing behavior. Importing a server entry does not automatically configure every app.

Start with one process or one browser. Confirm that local development services remain reachable and that DNS resolves as intended. An app with helper processes may need a broader rule than the launcher alone, but do not expand the rule until logs show what is missing.

For broader routing, test what happens when the client disconnects. Decide whether direct fallback is acceptable for the job. The Proxifier alternatives comparison explains the difference between a desktop GUI, a library wrapper and a virtual network interface.

Development tools, containers and AI assistants

A developer workflow can contain a native Mac process, a Linux VM and a cloud worker. Each may make its own network requests. Terminal environment variables only help software that reads them, and container or service configuration can be separate.

Docker distinguishes container proxy variables from daemon settings. Docker Desktop has its own proxy configuration. Use the documentation for the component you need to change; configuring a shell is not proof that image pulls or container requests take that route.

For Claude Code, the current enterprise network documentation lists HTTP/HTTPS proxy support and explicitly excludes SOCKS. Use a compatible endpoint for that client instead of assuming ALL_PROXY=socks5h://... works everywhere. Its model API connection remains separate from a browser launched by a tool.

A local Browser Use session needs browser configuration. A Browserbase session needs a remote proxy setting. For Cursor or another editor, check the current application's networking documentation and test the specific operation rather than assuming that one macOS proxy switch covers downloads, extensions and model requests alike.

Troubleshoot by comparing the same request

Safari works and Terminal fails

Specify the proxy explicitly in curl and compare the result. If it succeeds, inspect the failing tool's own configuration and supported protocol. The upstream is reachable; the next question is whether the tool is using it correctly.

Everything fails after changing networks

Check which network service is active and whether source-IP allowlisting still matches. A switch from Wi-Fi to Ethernet can change both local settings and the address reaching the provider.

Local development stops working

Review bypass rules for loopback and the private services you need. Keep exclusions narrow enough that public test traffic still takes the intended route. A hostname resolving to a local address and a literal IP can match rules differently.

The IP changed but the website's region did not

Check cookies, account locale, browser location permission and cached data. Network location is one input, not the entire localization system. Our SEO monitoring guide discusses keeping test conditions consistent.

Save a configuration you can reproduce

Record the app version, network service, endpoint protocol and intended traffic scope. Test exit IP, DNS and reconnection. For a long-lived account workflow, verify whether an upstream rotation interrupts the session before relying on it.

Keep a direct baseline and the rollback steps with the configuration. If a software update changes the routing behavior, repeat the same tests rather than adding another client on top. For dedicated mobile endpoints, choose the service's session behavior alongside its location.

Sources and review scope

This guide was checked against the documentation below on October 11, 2026. Software behavior depends on the installed version, operating system and proxy service. Configuration examples are illustrative; this is a documentation review, not a benchmark of every client.

Frequently asked questions

Continue with your device

Protocol basics, operating-system setup and client choices in one series.

Related workflows

Linux and Docker proxy layers

Separate terminal, daemon and container traffic.

Claude Code proxy setup

Use a supported network path for the API client.

Browser Use setup

Configure the browser independently of the model connection.

Quality-assurance proxies

Verify the network conditions used by a test.