Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

Configure the proxy endpoint and proxy credentials as two separate problems. Give Chrome the proxy host, port, and protocol through Selenium capabilities or --proxy-server; do not expect http://username:password@host:port to authenticate. Chromium states that Chrome does not use credentials embedded in manual proxy settings. A 407 response must therefore be handled by Chrome’s normal proxy-authentication flow, such as a compatible extension, browser policy, or an upstream gateway.

What actually has to be configured

A headless Selenium session has three independent layers:

  • Browser and driver compatibility: Selenium 4 supports Chrome 75 and later, and the ChromeDriver major version must match the Chrome browser major version.
  • Proxy selection: Chrome needs a proxy scheme, host, and port. You can provide these with a WebDriver proxy capability or a Chrome startup argument.
  • Proxy authentication: Credentials are supplied only after the proxy challenges the browser. They are not read from credentials embedded in the manual proxy URL.

Keeping these layers separate makes failures easier to diagnose. A browser that starts successfully can still bypass the proxy, and a correctly routed request can still receive 407 Proxy Authentication Required.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Prerequisites and version checks

Match Chrome and ChromeDriver

Install Selenium 4, Chrome, and ChromeDriver in the same execution environment. Check the browser’s major version and use a ChromeDriver with the same major version. Reproduce the same versions in CI, containers, and local development; a configuration that works locally can fail when the CI image has a different browser or driver.

Use a supported headless flag

Current Chrome uses a unified headless implementation. Selenium examples commonly use --headless=new; use the binding equivalent documented for the Chrome version installed in your environment. Headless mode is a startup option, not an authentication mechanism.

Collect the proxy details

Before writing code, obtain the exact proxy scheme, hostname, port, and authentication scheme from the proxy operator. Decide whether HTTP and HTTPS traffic use the same endpoint, whether a fallback proxy is needed, and which destinations must bypass the proxy.

Minimal Python setup: headless Chrome with a proxy endpoint

The following program is runnable and deliberately contains no username or password in the URL. It proves that Chrome starts in headless mode and sends navigation through the selected endpoint.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
from selenium import webdriver

options = webdriver.ChromeOptions()
options.add_argument('--headless=new')
options.add_argument('--proxy-server=http://proxy.example:8080')

driver = webdriver.Chrome(options=options)
try:
    driver.get('https://example.com')
    print(driver.title)
finally:
    driver.quit()

Replace the example host and port with the values supplied by your proxy provider. The --proxy-server value selects the endpoint; it does not answer an authentication challenge.

Why username:password@host:port fails

It is tempting to write http://user:[email protected]:8080. Chromium’s proxy design documentation explicitly says: “Chrome does not implement this, and will not use any credentials embedded in the proxy settings.” Chrome therefore reaches the proxy without usable credentials and receives a challenge. Repeated prompts or a 407 status are expected symptoms of this mismatch.

Rank #2
HP 14" HD Chromebook Laptop for Students, Intel Quad-Core N4120(> N4020), 4GB RAM, 64GB eMMC, WiFi, Webcam, HDMI, USB-A&C, 14 Hours Battery Life, Zoom, Chrome OS, CUE Accessories
  • Intel Celeron N4120: 4 Cores & Threads, 1.1GHz Base Clock, Up to 2.6GHz Boost Clock, 4MB Cache, Intel UHD Graphics 600. The perfect combination of performance, power consumption, and value helps your device handle multitasking smoothly and reliably with four processing cores to divide up the work.
  • 14" HD Display: 14.0-inch diagonal, HD (1366 x 768), micro-edge, anti-glare. See your digital world in a whole new way. Enjoy movies and photos with the great image quality and high-definition detail of 1 million pixels.
  • Memory & Storage: 4 GB LPDDR4x & 64 GB eMMC Storage. Adequate high-bandwidth RAM to smoothly run multiple applications and browser tabs all at once. An embedded multimedia card provides reliable flash-based storage.
  • Ports:2 x USB 3.0 Type-A,1 x USB 3.0 Type-C,1 x HDMI,1 x Headphone Jack
  • Chrome OS: Chromebook is a computer for the way the modern world works, with thousands of apps. Enjoy the seamless simplicity that comes with Google Chrome and Android apps, all integrated into one laptop. It’s fast, simple, and secure.

Do not “fix” this by printing credentials in logs or by repeatedly changing URL encoding. Keep secrets out of source control and command history, and choose an authentication mechanism that participates in Chrome’s ordinary challenge flow.

Ways to answer the proxy challenge

Use a compatible extension

An extension can listen for the browser’s proxy-authentication event and return credentials when the proxy challenges a request. Selenium loads the extension through ChromeOptions. The extension normally:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  1. Declares the proxy permission.
  2. Sets a fixed proxy configuration, commonly with a fixed_servers object and a singleProxy rule.
  3. Handles the authentication event and supplies the username and password without exposing them in the proxy URL.

Chrome’s proxy API also supports protocol-specific rules, a fallbackProxy, and a bypassList. Those fields control routing; they do not replace the authentication handler. Manifest version, event permissions, and the exact callback shape vary with the installed Chrome release, so validate the extension against that release and the proxy vendor’s authentication scheme.

Load a packed or unpacked extension using the Selenium binding’s ChromeOptions mechanism supported by your installed Selenium and Chrome versions. Test this in the same headless environment used in production: some extension packaging or permission combinations behave differently between local and CI images.

Use browser policy or an upstream gateway

In managed environments, browser policy can provide the organization’s approved proxy behavior. Another option is an upstream gateway that accepts credentials outside Chrome and exposes an endpoint that does not require interactive browser authentication. These approaches can simplify secret handling, but they must be approved and configured by the network administrator. They do not make embedded credentials in a Chrome proxy URL valid.

Rank #3
HP Chromebook 14 Laptop, Intel Celeron N4120, 4 GB RAM, 64 GB eMMC, 14" HD Display, Chrome OS, Thin Design, 4K Graphics, Long Battery Life, Ash Gray Keyboard (14a-na0226nr, 2022, Mineral Silver)
  • FOR HOME, WORK, & SCHOOL – With an Intel processor, 14-inch display, custom-tuned stereo speakers, and long battery life, this Chromebook laptop lets you knock out any assignment or binge-watch your favorite shows..Voltage:5.0 volts
  • HD DISPLAY, PORTABLE DESIGN – See every bit of detail on this micro-edge, anti-glare, 14-inch HD (1366 x 768) display (1); easily take this thin and lightweight laptop PC from room to room, on trips, or in a backpack.
  • ALL-DAY PERFORMANCE – Reliably tackle all your assignments at once with the quad-core, Intel Celeron N4120—the perfect processor for performance, power consumption, and value (2).
  • 4K READY – Smoothly stream 4K content and play your favorite next-gen games with Intel UHD Graphics 600 (3) (4).
  • MEMORY AND STORAGE – Enjoy a boost to your system’s performance with 4 GB of RAM while saving more of your favorite memories with 64 GB of reliable flash-based eMMC storage (5).

Confirm the authentication scheme

An extension that works for one proxy challenge may not work for another. Confirm whether the service expects the scheme supported by your extension, whether HTTPS traffic is routed through the same endpoint, and whether the provider requires an additional token or gateway step. The official Chrome and Selenium documentation describe the configuration surfaces, not a universal implementation for every proxy service.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Control HTTP, HTTPS, and bypass routing

Proxy selection is often the cause of an apparent authentication failure. Check all of these values before changing credential code:

  • Scheme: use the scheme the proxy operator specifies. An HTTP proxy endpoint and an HTTPS proxy endpoint are not interchangeable assumptions.
  • Host and port: verify spelling, DNS resolution, firewall access, and the listening port.
  • Protocol mappings: configure HTTPS or other protocol-specific proxy rules when required.
  • Fallback behavior: decide whether unmatched traffic should use a fallbackProxy or go direct.
  • Bypass list: exclude internal hosts only when that is intentional. A bypass rule can make a test appear to ignore the proxy.
  • Environment variables: inspect container and CI variables that may select a different proxy than your Chrome arguments.

When using a WebDriver proxy capability instead of --proxy-server, apply the equivalent HTTP, SSL, fallback, and bypass fields exposed by your Selenium binding. Do not configure one endpoint in capabilities and a conflicting endpoint in Chrome arguments.

Validate the same headless path used in production

  1. Start with the exact Chrome and ChromeDriver binaries used by the deployment.
  2. Run the minimal navigation script with the proxy endpoint but without credentials.
  3. Use a controlled test endpoint or an outbound-IP check to confirm that traffic is actually routed through the proxy.
  4. Record the HTTP status and browser logs. A 407 indicates a proxy challenge; a login page or 401 from the destination is target-site authentication and must be handled separately.
  5. Load the authentication extension or apply the approved policy, then repeat the same test.
  6. Test both an HTTP URL and an HTTPS URL when your workload uses both.

Do not infer success solely because Chrome opened a windowless session. A page can load from a bypassed destination while the proxy configuration is unused.

Troubleshooting common failures

Symptom Likely layer Checks and fixes
Chrome starts, but traffic bypasses the proxy Proxy selection Check --proxy-server or the WebDriver capability, scheme, host, port, bypass list, and proxy-related environment variables. Confirm the outbound IP from the same headless session.
HTTP 407 or a repeated credential prompt Authentication flow Remove embedded URL credentials. Use a compatible extension, browser policy, or upstream gateway that participates in the proxy-authentication challenge.
HTTP works but HTTPS fails Routing rules Configure the HTTPS or protocol-specific mapping, verify the proxy scheme, and check whether a fallback or bypass rule sends HTTPS elsewhere.
The extension does not load in headless Chrome Packaging and capabilities Use the packed or unpacked extension method supported by your Selenium and Chrome versions. Check manifest permissions and reproduce with the exact CI browser image.
Local and CI behavior differ Version or environment Match ChromeDriver and Chrome major versions, compare startup arguments and environment variables, and run with the same --headless=new mode.
The proxy works for one site but not another Destination or bypass policy Check the bypass list, protocol mapping, DNS behavior, and whether the second destination challenges for its own application credentials.

Credential and operational hygiene

  • Store proxy credentials in a secret manager or protected CI variables, not in source files, extension packages, screenshots, or logs.
  • Restrict access to the extension bundle and any generated profile that contains proxy settings.
  • Rotate credentials according to the proxy operator’s policy and invalidate leaked credentials immediately.
  • Use the smallest bypass list that satisfies your application; broad bypasses can silently defeat routing.
  • Keep a record of the Chrome, ChromeDriver, Selenium, extension manifest, and proxy versions used for each deployment.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Or skip the browser setup

If your actual goal is a clean image or PDF of a public page rather than interactive Selenium automation, ScreenshotNeo provides a single-request screenshot API and an MCP server for AI agents. It is not a replacement for browser automation that must click, log in, or interact with a private network, but it avoids maintaining ChromeDriver and proxy-authentication code for capture-only jobs.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #4
HP 14 2-in-1 Chromebook 14in FHD Intel CPU 4GB 64GB Storage (14b-Renewed)
  • 14" fhd ips touchscreen display with 360 flip; Intel 4k graphics
  • Intel n100 processor 4-core up to 3.40ghz, 4gb ddr5 ram, 64gb storage
  • 1x usb type c, 1x usb type a, 1x headphone microphone jack,
  • Super fast 6th gen wifi and bluetooth 5, 720p webcam with integrated dual array digital microphones
  • Chrome os, serenity blue color, ac charger included

Example cURL request (see the ScreenshotNeo API documentation):

curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp

The same request in Python:

import requests
r = requests.get('https://api.screenshotneo.com/v1/shot', params={'access_key': 'YOUR_API_KEY', 'url': 'https://stripe.com'}, timeout=90)
open('shot.webp', 'wb').write(r.content)

And in Node.js:

const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://stripe.com' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);

ScreenshotNeo accepts cookie and consent banners before capture and removes more than 60 known consent platforms, newsletter popups, and chat widgets; each cleanup step can be disabled. Bot checks or CAPTCHAs, blank pages, timeouts, failed loads, and cache hits are not billed, and the response identifies the page verdict and billing status in X-Page-Verdict and X-Billed headers. Its MCP server exposes take_screenshot, get_page_info, and capture_pdf for Claude, Cursor, and other MCP clients.

Every feature is included on every plan. The Free plan includes 1,000 screenshots per month with no card; paid plans start at $5 for 3,000 shots. Create an account at ScreenshotNeo’s free sign-up page.

Which approach should you choose?

Requirement Best fit Reason
Interact with a site through Selenium and a username/password proxy Selenium plus a compatible authentication extension, policy, or gateway Chrome must receive credentials through its normal proxy challenge flow.
Capture public pages without maintaining a browser stack ScreenshotNeo A single API call handles capture and reports whether the result was billable.
Use an organization-controlled network path Browser policy or an upstream gateway Network administrators can centralize credentials and routing.

Frequently Asked Questions

Is a 407 response the same as a website login failure?

No. A 407 is issued by the proxy before the request reaches the destination. A 401 or login form from the destination belongs to the website’s own authentication flow.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Can I put proxy credentials in a Chrome profile instead of an extension?

A profile can preserve browser settings, but Chromium still does not use credentials embedded in manual proxy settings. The challenge must be handled by a supported authentication mechanism.

Do I need a proxy for ScreenshotNeo?

The supplied ScreenshotNeo details describe its capture API and MCP server, not a proxy-authentication configuration. Use Selenium when your workflow specifically requires your own authenticated network path.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.